evp_cnf.c 1.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657
  1. /*
  2. * Copyright 2012-2016 The OpenSSL Project Authors. All Rights Reserved.
  3. *
  4. * Licensed under the OpenSSL license (the "License"). You may not use
  5. * this file except in compliance with the License. You can obtain a copy
  6. * in the file LICENSE in the source distribution or at
  7. * https://www.openssl.org/source/license.html
  8. */
  9. #include <stdio.h>
  10. #include <ctype.h>
  11. #include <openssl/crypto.h>
  12. #include "internal/cryptlib.h"
  13. #include <openssl/conf.h>
  14. #include <openssl/x509.h>
  15. #include <openssl/x509v3.h>
  16. /* Algorithm configuration module. */
  17. static int alg_module_init(CONF_IMODULE *md, const CONF *cnf)
  18. {
  19. int i;
  20. const char *oid_section;
  21. STACK_OF(CONF_VALUE) *sktmp;
  22. CONF_VALUE *oval;
  23. oid_section = CONF_imodule_get_value(md);
  24. if ((sktmp = NCONF_get_section(cnf, oid_section)) == NULL) {
  25. EVPerr(EVP_F_ALG_MODULE_INIT, EVP_R_ERROR_LOADING_SECTION);
  26. return 0;
  27. }
  28. for (i = 0; i < sk_CONF_VALUE_num(sktmp); i++) {
  29. oval = sk_CONF_VALUE_value(sktmp, i);
  30. if (strcmp(oval->name, "fips_mode") == 0) {
  31. int m;
  32. if (!X509V3_get_value_bool(oval, &m)) {
  33. EVPerr(EVP_F_ALG_MODULE_INIT, EVP_R_INVALID_FIPS_MODE);
  34. return 0;
  35. }
  36. if (m > 0) {
  37. EVPerr(EVP_F_ALG_MODULE_INIT, EVP_R_FIPS_MODE_NOT_SUPPORTED);
  38. return 0;
  39. }
  40. } else {
  41. EVPerr(EVP_F_ALG_MODULE_INIT, EVP_R_UNKNOWN_OPTION);
  42. ERR_add_error_data(4, "name=", oval->name,
  43. ", value=", oval->value);
  44. }
  45. }
  46. return 1;
  47. }
  48. void EVP_add_alg_module(void)
  49. {
  50. CONF_module_add("alg_section", alg_module_init, 0);
  51. }