isaacpittman-hitachi / rpms / openssl

Forked from rpms/openssl 2 years ago
Clone

Blame SOURCES/openssl-1.1.1-ec-curves.patch

0c50f5
diff -up openssl-1.1.1h/apps/speed.c.curves openssl-1.1.1h/apps/speed.c
0c50f5
--- openssl-1.1.1h/apps/speed.c.curves	2020-09-22 14:55:07.000000000 +0200
0c50f5
+++ openssl-1.1.1h/apps/speed.c	2020-11-06 13:27:15.659288431 +0100
782d48
@@ -490,90 +490,30 @@ static double rsa_results[RSA_NUM][2];
e4b8d1
 #endif /* OPENSSL_NO_RSA */
e4b8d1
 
782d48
 enum {
782d48
-    R_EC_P160,
782d48
-    R_EC_P192,
782d48
     R_EC_P224,
782d48
     R_EC_P256,
782d48
     R_EC_P384,
782d48
     R_EC_P521,
782d48
-#ifndef OPENSSL_NO_EC2M
782d48
-    R_EC_K163,
782d48
-    R_EC_K233,
782d48
-    R_EC_K283,
782d48
-    R_EC_K409,
782d48
-    R_EC_K571,
782d48
-    R_EC_B163,
782d48
-    R_EC_B233,
782d48
-    R_EC_B283,
782d48
-    R_EC_B409,
782d48
-    R_EC_B571,
782d48
-#endif
782d48
-    R_EC_BRP256R1,
782d48
-    R_EC_BRP256T1,
782d48
-    R_EC_BRP384R1,
782d48
-    R_EC_BRP384T1,
782d48
-    R_EC_BRP512R1,
782d48
-    R_EC_BRP512T1,
782d48
     R_EC_X25519,
782d48
     R_EC_X448
782d48
 };
782d48
 
e4b8d1
 #ifndef OPENSSL_NO_EC
e4b8d1
 static OPT_PAIR ecdsa_choices[] = {
e4b8d1
-    {"ecdsap160", R_EC_P160},
e4b8d1
-    {"ecdsap192", R_EC_P192},
e4b8d1
     {"ecdsap224", R_EC_P224},
e4b8d1
     {"ecdsap256", R_EC_P256},
e4b8d1
     {"ecdsap384", R_EC_P384},
e4b8d1
     {"ecdsap521", R_EC_P521},
782d48
-# ifndef OPENSSL_NO_EC2M
e4b8d1
-    {"ecdsak163", R_EC_K163},
e4b8d1
-    {"ecdsak233", R_EC_K233},
e4b8d1
-    {"ecdsak283", R_EC_K283},
e4b8d1
-    {"ecdsak409", R_EC_K409},
e4b8d1
-    {"ecdsak571", R_EC_K571},
e4b8d1
-    {"ecdsab163", R_EC_B163},
e4b8d1
-    {"ecdsab233", R_EC_B233},
e4b8d1
-    {"ecdsab283", R_EC_B283},
e4b8d1
-    {"ecdsab409", R_EC_B409},
e4b8d1
-    {"ecdsab571", R_EC_B571},
782d48
-# endif
e4b8d1
-    {"ecdsabrp256r1", R_EC_BRP256R1},
e4b8d1
-    {"ecdsabrp256t1", R_EC_BRP256T1},
e4b8d1
-    {"ecdsabrp384r1", R_EC_BRP384R1},
e4b8d1
-    {"ecdsabrp384t1", R_EC_BRP384T1},
e4b8d1
-    {"ecdsabrp512r1", R_EC_BRP512R1},
e4b8d1
-    {"ecdsabrp512t1", R_EC_BRP512T1}
e4b8d1
 };
e4b8d1
 # define ECDSA_NUM       OSSL_NELEM(ecdsa_choices)
e4b8d1
 
e4b8d1
 static double ecdsa_results[ECDSA_NUM][2];    /* 2 ops: sign then verify */
e4b8d1
 
e4b8d1
 static const OPT_PAIR ecdh_choices[] = {
e4b8d1
-    {"ecdhp160", R_EC_P160},
e4b8d1
-    {"ecdhp192", R_EC_P192},
e4b8d1
     {"ecdhp224", R_EC_P224},
e4b8d1
     {"ecdhp256", R_EC_P256},
e4b8d1
     {"ecdhp384", R_EC_P384},
e4b8d1
     {"ecdhp521", R_EC_P521},
782d48
-# ifndef OPENSSL_NO_EC2M
e4b8d1
-    {"ecdhk163", R_EC_K163},
e4b8d1
-    {"ecdhk233", R_EC_K233},
e4b8d1
-    {"ecdhk283", R_EC_K283},
e4b8d1
-    {"ecdhk409", R_EC_K409},
e4b8d1
-    {"ecdhk571", R_EC_K571},
e4b8d1
-    {"ecdhb163", R_EC_B163},
e4b8d1
-    {"ecdhb233", R_EC_B233},
e4b8d1
-    {"ecdhb283", R_EC_B283},
e4b8d1
-    {"ecdhb409", R_EC_B409},
e4b8d1
-    {"ecdhb571", R_EC_B571},
782d48
-# endif
e4b8d1
-    {"ecdhbrp256r1", R_EC_BRP256R1},
e4b8d1
-    {"ecdhbrp256t1", R_EC_BRP256T1},
e4b8d1
-    {"ecdhbrp384r1", R_EC_BRP384R1},
e4b8d1
-    {"ecdhbrp384t1", R_EC_BRP384T1},
e4b8d1
-    {"ecdhbrp512r1", R_EC_BRP512R1},
e4b8d1
-    {"ecdhbrp512t1", R_EC_BRP512T1},
e4b8d1
     {"ecdhx25519", R_EC_X25519},
e4b8d1
     {"ecdhx448", R_EC_X448}
e4b8d1
 };
0c50f5
@@ -1502,31 +1442,10 @@ int speed_main(int argc, char **argv)
e4b8d1
         unsigned int bits;
e4b8d1
     } test_curves[] = {
e4b8d1
         /* Prime Curves */
e4b8d1
-        {"secp160r1", NID_secp160r1, 160},
e4b8d1
-        {"nistp192", NID_X9_62_prime192v1, 192},
e4b8d1
         {"nistp224", NID_secp224r1, 224},
e4b8d1
         {"nistp256", NID_X9_62_prime256v1, 256},
782d48
         {"nistp384", NID_secp384r1, 384},
e4b8d1
         {"nistp521", NID_secp521r1, 521},
782d48
-# ifndef OPENSSL_NO_EC2M
e4b8d1
-        /* Binary Curves */
e4b8d1
-        {"nistk163", NID_sect163k1, 163},
782d48
-        {"nistk233", NID_sect233k1, 233},
e4b8d1
-        {"nistk283", NID_sect283k1, 283},
e4b8d1
-        {"nistk409", NID_sect409k1, 409},
e4b8d1
-        {"nistk571", NID_sect571k1, 571},
e4b8d1
-        {"nistb163", NID_sect163r2, 163},
e4b8d1
-        {"nistb233", NID_sect233r1, 233},
e4b8d1
-        {"nistb283", NID_sect283r1, 283},
e4b8d1
-        {"nistb409", NID_sect409r1, 409},
e4b8d1
-        {"nistb571", NID_sect571r1, 571},
782d48
-# endif
e4b8d1
-        {"brainpoolP256r1", NID_brainpoolP256r1, 256},
e4b8d1
-        {"brainpoolP256t1", NID_brainpoolP256t1, 256},
e4b8d1
-        {"brainpoolP384r1", NID_brainpoolP384r1, 384},
e4b8d1
-        {"brainpoolP384t1", NID_brainpoolP384t1, 384},
e4b8d1
-        {"brainpoolP512r1", NID_brainpoolP512r1, 512},
e4b8d1
-        {"brainpoolP512t1", NID_brainpoolP512t1, 512},
e4b8d1
         /* Other and ECDH only ones */
e4b8d1
         {"X25519", NID_X25519, 253},
e4b8d1
         {"X448", NID_X448, 448}
0c50f5
@@ -2026,9 +1945,9 @@ int speed_main(int argc, char **argv)
e4b8d1
 #  endif
e4b8d1
 
e4b8d1
 #  ifndef OPENSSL_NO_EC
e4b8d1
-    ecdsa_c[R_EC_P160][0] = count / 1000;
e4b8d1
-    ecdsa_c[R_EC_P160][1] = count / 1000 / 2;
e4b8d1
-    for (i = R_EC_P192; i <= R_EC_P521; i++) {
e4b8d1
+    ecdsa_c[R_EC_P224][0] = count / 1000;
e4b8d1
+    ecdsa_c[R_EC_P224][1] = count / 1000 / 2;
e4b8d1
+    for (i = R_EC_P256; i <= R_EC_P521; i++) {
e4b8d1
         ecdsa_c[i][0] = ecdsa_c[i - 1][0] / 2;
e4b8d1
         ecdsa_c[i][1] = ecdsa_c[i - 1][1] / 2;
e4b8d1
         if (ecdsa_doit[i] <= 1 && ecdsa_c[i][0] == 0)
0c50f5
@@ -2040,7 +1959,7 @@ int speed_main(int argc, char **argv)
e4b8d1
             }
e4b8d1
         }
e4b8d1
     }
782d48
-#   ifndef OPENSSL_NO_EC2M
782d48
+#   if 0
e4b8d1
     ecdsa_c[R_EC_K163][0] = count / 1000;
e4b8d1
     ecdsa_c[R_EC_K163][1] = count / 1000 / 2;
e4b8d1
     for (i = R_EC_K233; i <= R_EC_K571; i++) {
0c50f5
@@ -2071,8 +1990,8 @@ int speed_main(int argc, char **argv)
e4b8d1
     }
782d48
 #   endif
782d48
 
e4b8d1
-    ecdh_c[R_EC_P160][0] = count / 1000;
e4b8d1
-    for (i = R_EC_P192; i <= R_EC_P521; i++) {
e4b8d1
+    ecdh_c[R_EC_P224][0] = count / 1000;
e4b8d1
+    for (i = R_EC_P256; i <= R_EC_P521; i++) {
e4b8d1
         ecdh_c[i][0] = ecdh_c[i - 1][0] / 2;
e4b8d1
         if (ecdh_doit[i] <= 1 && ecdh_c[i][0] == 0)
e4b8d1
             ecdh_doit[i] = 0;
0c50f5
@@ -2082,7 +2001,7 @@ int speed_main(int argc, char **argv)
e4b8d1
             }
e4b8d1
         }
e4b8d1
     }
782d48
-#   ifndef OPENSSL_NO_EC2M
782d48
+#   if 0
e4b8d1
     ecdh_c[R_EC_K163][0] = count / 1000;
e4b8d1
     for (i = R_EC_K233; i <= R_EC_K571; i++) {
e4b8d1
         ecdh_c[i][0] = ecdh_c[i - 1][0] / 2;
0c50f5
diff -up openssl-1.1.1h/crypto/ec/ecp_smpl.c.curves openssl-1.1.1h/crypto/ec/ecp_smpl.c
0c50f5
--- openssl-1.1.1h/crypto/ec/ecp_smpl.c.curves	2020-09-22 14:55:07.000000000 +0200
0c50f5
+++ openssl-1.1.1h/crypto/ec/ecp_smpl.c	2020-11-06 13:27:15.659288431 +0100
782d48
@@ -145,6 +145,11 @@ int ec_GFp_simple_group_set_curve(EC_GRO
e4b8d1
         return 0;
e4b8d1
     }
e4b8d1
 
e4b8d1
+    if (BN_num_bits(p) < 224) {
e4b8d1
+        ECerr(EC_F_EC_GFP_SIMPLE_GROUP_SET_CURVE, EC_R_UNSUPPORTED_FIELD);
e4b8d1
+        return 0;
e4b8d1
+    }
e4b8d1
+
e4b8d1
     if (ctx == NULL) {
e4b8d1
         ctx = new_ctx = BN_CTX_new();
e4b8d1
         if (ctx == NULL)
0c50f5
diff -up openssl-1.1.1h/test/ecdsatest.h.curves openssl-1.1.1h/test/ecdsatest.h
0c50f5
--- openssl-1.1.1h/test/ecdsatest.h.curves	2020-11-06 13:27:15.627288114 +0100
0c50f5
+++ openssl-1.1.1h/test/ecdsatest.h	2020-11-06 13:27:15.660288441 +0100
782d48
@@ -32,23 +32,6 @@ typedef struct {
782d48
 } ecdsa_cavs_kat_t;
e4b8d1
 
782d48
 static const ecdsa_cavs_kat_t ecdsa_cavs_kats[] = {
782d48
-    /* prime KATs from X9.62 */
782d48
-    {NID_X9_62_prime192v1, NID_sha1,
782d48
-     "616263",                  /* "abc" */
782d48
-     "1a8d598fc15bf0fd89030b5cb1111aeb92ae8baf5ea475fb",
782d48
-     "0462b12d60690cdcf330babab6e69763b471f994dd702d16a563bf5ec08069705ffff65e"
782d48
-     "5ca5c0d69716dfcb3474373902",
782d48
-     "fa6de29746bbeb7f8bb1e761f85f7dfb2983169d82fa2f4e",
782d48
-     "885052380ff147b734c330c43d39b2c4a89f29b0f749fead",
782d48
-     "e9ecc78106def82bf1070cf1d4d804c3cb390046951df686"},
782d48
-    {NID_X9_62_prime239v1, NID_sha1,
782d48
-     "616263",                  /* "abc" */
782d48
-     "7ef7c6fabefffdea864206e80b0b08a9331ed93e698561b64ca0f7777f3d",
782d48
-     "045b6dc53bc61a2548ffb0f671472de6c9521a9d2d2534e65abfcbd5fe0c707fd9f1ed2e"
782d48
-     "65f09f6ce0893baf5e8e31e6ae82ea8c3592335be906d38dee",
782d48
-     "656c7196bf87dcc5d1f1020906df2782360d36b2de7a17ece37d503784af",
782d48
-     "2cb7f36803ebb9c427c58d8265f11fc5084747133078fc279de874fbecb0",
782d48
-     "2eeae988104e9c2234a3c2beb1f53bfa5dc11ff36a875d1e3ccb1f7e45cf"},
782d48
     /* prime KATs from NIST CAVP */
782d48
     {NID_secp224r1, NID_sha224,
782d48
      "699325d6fc8fbbb4981a6ded3c3a54ad2e4e3db8a5669201912064c64e700c139248cdc1"
0c50f5
--- openssl-1.1.1h/test/recipes/15-test_genec.t.ec-curves	2020-11-06 13:58:36.402895540 +0100
0c50f5
+++ openssl-1.1.1h/test/recipes/15-test_genec.t	2020-11-06 13:59:38.508484498 +0100
0c50f5
@@ -20,45 +20,11 @@ plan skip_all => "This test is unsupport
0c50f5
     if disabled("ec");
0c50f5
 
0c50f5
 my @prime_curves = qw(
0c50f5
-    secp112r1
0c50f5
-    secp112r2
0c50f5
-    secp128r1
0c50f5
-    secp128r2
0c50f5
-    secp160k1
0c50f5
-    secp160r1
0c50f5
-    secp160r2
0c50f5
-    secp192k1
0c50f5
-    secp224k1
0c50f5
     secp224r1
0c50f5
     secp256k1
0c50f5
     secp384r1
0c50f5
     secp521r1
0c50f5
-    prime192v1
0c50f5
-    prime192v2
0c50f5
-    prime192v3
0c50f5
-    prime239v1
0c50f5
-    prime239v2
0c50f5
-    prime239v3
0c50f5
     prime256v1
0c50f5
-    wap-wsg-idm-ecid-wtls6
0c50f5
-    wap-wsg-idm-ecid-wtls7
0c50f5
-    wap-wsg-idm-ecid-wtls8
0c50f5
-    wap-wsg-idm-ecid-wtls9
0c50f5
-    wap-wsg-idm-ecid-wtls12
0c50f5
-    brainpoolP160r1
0c50f5
-    brainpoolP160t1
0c50f5
-    brainpoolP192r1
0c50f5
-    brainpoolP192t1
0c50f5
-    brainpoolP224r1
0c50f5
-    brainpoolP224t1
0c50f5
-    brainpoolP256r1
0c50f5
-    brainpoolP256t1
0c50f5
-    brainpoolP320r1
0c50f5
-    brainpoolP320t1
0c50f5
-    brainpoolP384r1
0c50f5
-    brainpoolP384t1
0c50f5
-    brainpoolP512r1
0c50f5
-    brainpoolP512t1
0c50f5
 );
0c50f5
 
0c50f5
 my @binary_curves = qw(
0c50f5
@@ -115,7 +81,6 @@ push(@other_curves, 'SM2')
0c50f5
     if !disabled("sm2");
0c50f5
 
0c50f5
 my @curve_aliases = qw(
0c50f5
-    P-192
0c50f5
     P-224
0c50f5
     P-256
0c50f5
     P-384