Blame SOURCES/gnutls-3.6.8-fips-aes-cbc-kat.patch

62aa50
From facea2b7659e11efce7014bda8800574d35dd05d Mon Sep 17 00:00:00 2001
62aa50
From: Daiki Ueno <dueno@redhat.com>
62aa50
Date: Wed, 12 Jun 2019 14:02:05 +0200
62aa50
Subject: [PATCH] fips: run selftests over overridden AES-CBC algorithm
62aa50
62aa50
Previously, we only tested nettle's AES-CBC in
62aa50
_gnutls_fips_perform_self_checks1(), which is called before the
62aa50
implementation is overridden.  This adds an AES-CBC self-test in
62aa50
_gnutls_fips_perform_self_checks2() so it can test the actual
62aa50
implementation.
62aa50
62aa50
Signed-off-by: Daiki Ueno <dueno@redhat.com>
62aa50
---
62aa50
 lib/fips.c | 6 ++++++
62aa50
 1 file changed, 6 insertions(+)
62aa50
62aa50
diff --git a/lib/fips.c b/lib/fips.c
62aa50
index b92edbbd7..902af5674 100644
62aa50
--- a/lib/fips.c
62aa50
+++ b/lib/fips.c
62aa50
@@ -317,6 +317,12 @@ int _gnutls_fips_perform_self_checks2(void)
62aa50
 		goto error;
62aa50
 	}
62aa50
 
62aa50
+	ret = gnutls_cipher_self_test(0, GNUTLS_CIPHER_AES_256_CBC);
62aa50
+	if (ret < 0) {
62aa50
+		gnutls_assert();
62aa50
+		goto error;
62aa50
+	}
62aa50
+
62aa50
 	ret = gnutls_cipher_self_test(0, GNUTLS_CIPHER_AES_256_GCM);
62aa50
 	if (ret < 0) {
62aa50
 		gnutls_assert();
62aa50
-- 
62aa50
2.20.1
62aa50