|
41 | 41 | log = logging.getLogger("multissl")
|
42 | 42 |
|
43 | 43 | OPENSSL_OLD_VERSIONS = [
|
44 |
| - "1.0.2", |
45 | 44 | ]
|
46 | 45 |
|
47 | 46 | OPENSSL_RECENT_VERSIONS = [
|
48 |
| - "1.0.2t", |
| 47 | + "1.0.2u", |
49 | 48 | "1.1.0l",
|
50 |
| - "1.1.1f", |
| 49 | + "1.1.1g", |
| 50 | + # "3.0.0-alpha2" |
51 | 51 | ]
|
52 | 52 |
|
53 | 53 | LIBRESSL_OLD_VERSIONS = [
|
|
143 | 143 | help="Keep original sources for debugging."
|
144 | 144 | )
|
145 | 145 |
|
| 146 | +OPENSSL_FIPS_CNF = """\ |
| 147 | +openssl_conf = openssl_init |
| 148 | +
|
| 149 | +.include {self.install_dir}/ssl/fipsinstall.cnf |
| 150 | +# .include {self.install_dir}/ssl/openssl.cnf |
| 151 | +
|
| 152 | +[openssl_init] |
| 153 | +providers = provider_sect |
| 154 | +
|
| 155 | +[provider_sect] |
| 156 | +fips = fips_sect |
| 157 | +default = default_sect |
| 158 | +
|
| 159 | +[default_sect] |
| 160 | +activate = 1 |
| 161 | +""" |
| 162 | + |
146 | 163 |
|
147 | 164 | class AbstractBuilder(object):
|
148 | 165 | library = None
|
@@ -291,9 +308,13 @@ def _make_install(self):
|
291 | 308 | ["make", "-j1", self.install_target],
|
292 | 309 | cwd=self.build_dir
|
293 | 310 | )
|
| 311 | + self._post_install() |
294 | 312 | if not self.args.keep_sources:
|
295 | 313 | shutil.rmtree(self.build_dir)
|
296 | 314 |
|
| 315 | + def _post_install(self): |
| 316 | + pass |
| 317 | + |
297 | 318 | def install(self):
|
298 | 319 | log.info(self.openssl_cli)
|
299 | 320 | if not self.has_openssl or self.args.force:
|
@@ -365,6 +386,40 @@ class BuildOpenSSL(AbstractBuilder):
|
365 | 386 | # only install software, skip docs
|
366 | 387 | install_target = 'install_sw'
|
367 | 388 |
|
| 389 | + def _post_install(self): |
| 390 | + if self.version.startswith("3.0"): |
| 391 | + self._post_install_300() |
| 392 | + |
| 393 | + def _post_install_300(self): |
| 394 | + # create ssl/ subdir with example configs |
| 395 | + self._subprocess_call( |
| 396 | + ["make", "-j1", "install_ssldirs"], |
| 397 | + cwd=self.build_dir |
| 398 | + ) |
| 399 | + # Install FIPS module |
| 400 | + # https://wiki.openssl.org/index.php/OpenSSL_3.0#Completing_the_installation_of_the_FIPS_Module |
| 401 | + fipsinstall_cnf = os.path.join( |
| 402 | + self.install_dir, "ssl", "fipsinstall.cnf" |
| 403 | + ) |
| 404 | + openssl_fips_cnf = os.path.join( |
| 405 | + self.install_dir, "ssl", "openssl-fips.cnf" |
| 406 | + ) |
| 407 | + fips_mod = os.path.join(self.lib_dir, "ossl-modules/fips.so") |
| 408 | + self._subprocess_call( |
| 409 | + [ |
| 410 | + self.openssl_cli, "fipsinstall", |
| 411 | + "-out", fipsinstall_cnf, |
| 412 | + "-module", fips_mod, |
| 413 | + "-provider_name", "fips", |
| 414 | + "-mac_name", "HMAC", |
| 415 | + "-macopt", "digest:SHA256", |
| 416 | + "-macopt", "hexkey:00", |
| 417 | + "-section_name", "fips_sect" |
| 418 | + ] |
| 419 | + ) |
| 420 | + with open(openssl_fips_cnf, "w") as f: |
| 421 | + f.write(OPENSSL_FIPS_CNF.format(self=self)) |
| 422 | + |
368 | 423 |
|
369 | 424 | class BuildLibreSSL(AbstractBuilder):
|
370 | 425 | library = "LibreSSL"
|
|
0 commit comments