-
Notifications
You must be signed in to change notification settings - Fork 77
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
OpenSSL FIPS provider support #262
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Signed-off-by: He, Jing J <jing.j.he@intel.com>
build option. Co-authored-by: Juan del Cuvillo <juan.b.del.cuvillo@intel.com> Signed-off-by: Jing He <jing.j.he@intel.com> Signed-off-by: Juan del Cuvillo <juan.b.del.cuvillo@intel.com>
Signed-off-by: Jing He <jing.j.he@intel.com>
Signed-off-by: Jing He <jing.j.he@intel.com>
Signed-off-by: Jing He <jing.j.he@intel.com>
Signed-off-by: Jing He <jing.j.he@intel.com>
Signed-off-by: Jing He <jing.j.he@intel.com>
self-test was failing due to the additional reseeding caused by using the RDTSC instruction. Signed-off-by: Jing He <jing.j.he@intel.com>
Signed-off-by: Jing He <jing.j.he@intel.com>
"make all FIPS=1; make test FIPS=1" shows the OpenSSL FIP provider working inside an enclave. Signed-off-by: Jing He <jing.j.he@intel.com>
The new Makefile provides the standard targets: all, clean, install and uninstall that the main Mafile calls when the option FIPS is set. Signed-off-by: Juan del Cuvillo <juan.b.del.cuvillo@intel.com>
the FIPS provider. Execute the install target first. Signed-off-by: Juan del Cuvillo <juan.b.del.cuvillo@intel.com>
provider inside an enclave. Signed-off-by: Juan del Cuvillo <juan.b.del.cuvillo@intel.com>
although it isn't currently supported. It appears that RAND_R_INVALID_PROPERTY_QUERY was added to randerr.h in OpenSSL 3.1.6. Signed-off-by: Juan del Cuvillo <juan.b.del.cuvillo@intel.com>
file in CONF_modules_load_file_ex. Signed-off-by: Juan del Cuvillo <juan.b.del.cuvillo@intel.com>
Signed-off-by: Juan del Cuvillo <juan.b.del.cuvillo@intel.com>
Looks good to me |
lzha101
reviewed
Dec 9, 2024
lzha101
reviewed
Dec 9, 2024
jbdelcuv
commented
Dec 9, 2024
Signed-off-by: Juan del Cuvillo <juan.b.del.cuvillo@intel.com>
Signed-off-by: Juan del Cuvillo <juan.b.del.cuvillo@intel.com>
lzha101
reviewed
Dec 10, 2024
lzha101
reviewed
Dec 16, 2024
Signed-off-by: Juan del Cuvillo <juan.b.del.cuvillo@intel.com>
Both sample apps include a template from which an OpenSSL configuration file is generated rather than copying one from the SGX SDK.
This reverts commit 7d10ac4.
Both sample apps include a template from which an OpenSSL configuration file is be generated rather than copying one from the SGX SDK. Signed-off-by: Juan del Cuvillo <juan.b.del.cuvillo@intel.com>
lzha101
reviewed
Dec 20, 2024
lzha101
reviewed
Dec 20, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Add support to the SGX-SSL library to have crypto algorithms run in the FIPS provider embedded in enclave images.
Instructions for building/testing, assuming you have an updated SGX SDK/PSW toolchain available:
Instructions for cleaning up: