From b1caa48e4bb3f15e7eb749e0c3470436ebff3435 Mon Sep 17 00:00:00 2001 From: Michael Brown Date: Sun, 2 Aug 2015 16:54:24 +0100 Subject: [crypto] Support SHA-{224,384,512} in X.509 certificates Add support for SHA-224, SHA-384, and SHA-512 as digest algorithms in X.509 certificates, and allow the choice of public-key, cipher, and digest algorithms to be configured at build time via config/crypto.h. Originally-implemented-by: Tufan Karadere Signed-off-by: Michael Brown --- src/config/crypto.h | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) (limited to 'src/config/crypto.h') diff --git a/src/config/crypto.h b/src/config/crypto.h index 9e1f8b2f7..bccfc04b8 100644 --- a/src/config/crypto.h +++ b/src/config/crypto.h @@ -9,6 +9,39 @@ FILE_LICENCE ( GPL2_OR_LATER_OR_UBDL ); +/** RSA public-key algorithm */ +#define CRYPTO_PUBKEY_RSA + +/** AES-CBC block cipher */ +#define CRYPTO_CIPHER_AES_CBC + +/** MD5 digest algorithm + * + * Note that use of MD5 is implicit when using TLSv1.1 or earlier. + */ +#define CRYPTO_DIGEST_MD5 + +/** SHA-1 digest algorithm + * + * Note that use of SHA-1 is implicit when using TLSv1.1 or earlier. + */ +#define CRYPTO_DIGEST_SHA1 + +/** SHA-224 digest algorithm */ +#define CRYPTO_DIGEST_SHA224 + +/** SHA-256 digest algorithm + * + * Note that use of SHA-256 is implicit when using TLSv1.2. + */ +#define CRYPTO_DIGEST_SHA256 + +/** SHA-384 digest algorithm */ +#define CRYPTO_DIGEST_SHA384 + +/** SHA-512 digest algorithm */ +#define CRYPTO_DIGEST_SHA512 + /** Margin of error (in seconds) allowed in signed timestamps * * We default to allowing a reasonable margin of error: 12 hours to -- cgit v1.2.3-55-g7522