Blob Blame History Raw
From 50d864024d5f165e3a649371c811cefd695fc2db Mon Sep 17 00:00:00 2001
From: Andrew Bartlett <abartlet@samba.org>
Date: Thu, 15 Aug 2019 14:25:41 +1200
Subject: [PATCH 104/187] build: Set minimum GnuTLS version at 3.4.7

This will soon be required for encrypted_secrets in the AD DC, the BackupKey server
and SMB2 as we remove use of the internal AES code.

Signed-off-by: Andrew Bartlett <abartlet@samba.org>
Reviewed-by: Andreas Schneider <asn@samba.org>
(cherry picked from commit 974cebdf953259f41ecfc7375bc31d72af53f51e)
---
 wscript_configure_system_gnutls | 11 +----------
 1 file changed, 1 insertion(+), 10 deletions(-)

diff --git a/wscript_configure_system_gnutls b/wscript_configure_system_gnutls
index 85824aad4ed..8ff0529e10c 100644
--- a/wscript_configure_system_gnutls
+++ b/wscript_configure_system_gnutls
@@ -1,17 +1,9 @@
 from waflib import Options
 
-gnutls_min_required_version = "3.2.0"
+gnutls_min_required_version = "3.4.7"
 
 gnutls_required_version = gnutls_min_required_version
 
-#
-# If we build with MIT Kerberos we need at least GnuTLS 3.4.7 for the backupkey
-# protocol.
-#
-if Options.options.with_system_mitkrb5 and conf.env.AD_DC_BUILD_IS_ENABLED:
-    gnutls_required_version = "3.4.7"
-    conf.DEFINE('HAVE_GNUTLS_3_4_7', 1)
-
 conf.CHECK_CFG(package='gnutls',
                args=('"gnutls >= %s" --cflags --libs' % gnutls_required_version),
                      msg='Checking for GnuTLS >= %s' % gnutls_required_version,
@@ -39,6 +31,5 @@ else:
 
 if conf.CHECK_VALUEOF('GNUTLS_CIPHER_AES_128_CFB8', headers='gnutls/gnutls.h'):
     conf.DEFINE('HAVE_GNUTLS_AES_CFB8', 1)
-    conf.DEFINE('HAVE_GNUTLS_3_4_7', 1)
 else:
     Logs.warn('No gnutls support for AES CFB8')
-- 
2.23.0