|
43 | 43 | OPENSSL_OLD_VERSIONS = [
|
44 | 44 | "0.9.8zh",
|
45 | 45 | "1.0.1u",
|
46 |
| - "1.0.2", |
47 | 46 | ]
|
48 | 47 |
|
49 | 48 | OPENSSL_RECENT_VERSIONS = [
|
50 |
| - "1.0.2p", |
51 |
| - "1.1.0i", |
52 |
| - "1.1.1k", |
53 |
| - "3.0.3", |
| 49 | + "1.0.2u", |
| 50 | + "1.1.0l", |
| 51 | + "1.1.1g", |
| 52 | + # "3.0.0-alpha2" |
54 | 53 | ]
|
55 | 54 |
|
56 | 55 | LIBRESSL_OLD_VERSIONS = [
|
|
148 | 147 | help="Keep original sources for debugging."
|
149 | 148 | )
|
150 | 149 |
|
| 150 | +OPENSSL_FIPS_CNF = """\ |
| 151 | +openssl_conf = openssl_init |
| 152 | +
|
| 153 | +.include {self.install_dir}/ssl/fipsinstall.cnf |
| 154 | +# .include {self.install_dir}/ssl/openssl.cnf |
| 155 | +
|
| 156 | +[openssl_init] |
| 157 | +providers = provider_sect |
| 158 | +
|
| 159 | +[provider_sect] |
| 160 | +fips = fips_sect |
| 161 | +default = default_sect |
| 162 | +
|
| 163 | +[default_sect] |
| 164 | +activate = 1 |
| 165 | +""" |
| 166 | + |
151 | 167 |
|
152 | 168 | class AbstractBuilder(object):
|
153 | 169 | library = None
|
@@ -296,9 +312,13 @@ def _make_install(self):
|
296 | 312 | ["make", "-j1", self.install_target],
|
297 | 313 | cwd=self.build_dir
|
298 | 314 | )
|
| 315 | + self._post_install() |
299 | 316 | if not self.args.keep_sources:
|
300 | 317 | shutil.rmtree(self.build_dir)
|
301 | 318 |
|
| 319 | + def _post_install(self): |
| 320 | + pass |
| 321 | + |
302 | 322 | def install(self):
|
303 | 323 | log.info(self.openssl_cli)
|
304 | 324 | if not self.has_openssl or self.args.force:
|
@@ -370,6 +390,40 @@ class BuildOpenSSL(AbstractBuilder):
|
370 | 390 | # only install software, skip docs
|
371 | 391 | install_target = 'install_sw'
|
372 | 392 |
|
| 393 | + def _post_install(self): |
| 394 | + if self.version.startswith("3.0"): |
| 395 | + self._post_install_300() |
| 396 | + |
| 397 | + def _post_install_300(self): |
| 398 | + # create ssl/ subdir with example configs |
| 399 | + self._subprocess_call( |
| 400 | + ["make", "-j1", "install_ssldirs"], |
| 401 | + cwd=self.build_dir |
| 402 | + ) |
| 403 | + # Install FIPS module |
| 404 | + # https://wiki.openssl.org/index.php/OpenSSL_3.0#Completing_the_installation_of_the_FIPS_Module |
| 405 | + fipsinstall_cnf = os.path.join( |
| 406 | + self.install_dir, "ssl", "fipsinstall.cnf" |
| 407 | + ) |
| 408 | + openssl_fips_cnf = os.path.join( |
| 409 | + self.install_dir, "ssl", "openssl-fips.cnf" |
| 410 | + ) |
| 411 | + fips_mod = os.path.join(self.lib_dir, "ossl-modules/fips.so") |
| 412 | + self._subprocess_call( |
| 413 | + [ |
| 414 | + self.openssl_cli, "fipsinstall", |
| 415 | + "-out", fipsinstall_cnf, |
| 416 | + "-module", fips_mod, |
| 417 | + "-provider_name", "fips", |
| 418 | + "-mac_name", "HMAC", |
| 419 | + "-macopt", "digest:SHA256", |
| 420 | + "-macopt", "hexkey:00", |
| 421 | + "-section_name", "fips_sect" |
| 422 | + ] |
| 423 | + ) |
| 424 | + with open(openssl_fips_cnf, "w") as f: |
| 425 | + f.write(OPENSSL_FIPS_CNF.format(self=self)) |
| 426 | + |
373 | 427 |
|
374 | 428 | class BuildLibreSSL(AbstractBuilder):
|
375 | 429 | library = "LibreSSL"
|
|
0 commit comments