mirror of
https://github.com/opnsense/src.git
synced 2026-06-08 00:02:14 -04:00
Summary: Release notes can be found at https://www.openssl.org/news/openssl-3.0-notes.html . Obtained from: https://www.openssl.org/source/openssl-3.0.8.tar.gz Differential Revision: https://reviews.freebsd.org/D38835 Test Plan: ``` $ git status On branch vendor/openssl-3.0 nothing to commit, working tree clean $ (cd ..; fetch http://www.openssl.org/source/openssl-${OSSLVER}.tar.gz http://www.openssl.org/source/openssl-${OSSLVER}.tar.gz.asc) openssl-3.0.8.tar.gz 14 MB 4507 kBps 04s openssl-3.0.8.tar.gz.asc 833 B 10 MBps 00s $ set | egrep '(XLIST|OSSLVER)=' OSSLVER=3.0.8 XLIST=FREEBSD-Xlist $ gpg --list-keys /home/ngie/.gnupg/pubring.kbx ----------------------------- pub rsa4096 2014-10-04 [SC] 7953AC1FBC3DC8B3B292393ED5E9E43F7DF9EE8C uid [ unknown] Richard Levitte <richard@levitte.org> uid [ unknown] Richard Levitte <levitte@lp.se> uid [ unknown] Richard Levitte <levitte@openssl.org> sub rsa4096 2014-10-04 [E] $ gpg --verify openssl-${OSSLVER}.tar.gz.asc openssl-${OSSLVER}.tar.gz gpg: Signature made Tue Feb 7 05:43:55 2023 PST gpg: using RSA key 7953AC1FBC3DC8B3B292393ED5E9E43F7DF9EE8C gpg: Good signature from "Richard Levitte <richard@levitte.org>" [unknown] gpg: aka "Richard Levitte <levitte@lp.se>" [unknown] gpg: aka "Richard Levitte <levitte@openssl.org>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: 7953 AC1F BC3D C8B3 B292 393E D5E9 E43F 7DF9 EE8C $ (cd vendor.checkout/; git status; find . -type f -or -type l | cut -c 3- | sort > ../old) On branch vendor/openssl-3.0 nothing to commit, working tree clean $ tar -x -X $XLIST -f ../openssl-${OSSLVER}.tar.gz -C .. $ rsync --exclude FREEBSD.* --delete -avzz ../openssl-${OSSLVER}/* . $ cat .git gitdir: /home/ngie/git/freebsd-src/.git/worktrees/vendor.checkout $ diff -arq ../openssl-3.0.8 . Only in .: .git Only in .: FREEBSD-Xlist Only in .: FREEBSD-upgrade $ git status FREEBSD* On branch vendor/openssl-3.0 nothing to commit, working tree clean $ ``` Reviewers: emaste, jkim Subscribers: imp, andrew, dab Differential Revision: https://reviews.freebsd.org/D38835
123 lines
3.8 KiB
C
123 lines
3.8 KiB
C
/*
|
|
* Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
|
|
*
|
|
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
|
* this file except in compliance with the License. You can obtain a copy
|
|
* in the file LICENSE in the source distribution or at
|
|
* https://www.openssl.org/source/license.html
|
|
*/
|
|
|
|
#ifndef OPENSSL_RAND_H
|
|
# define OPENSSL_RAND_H
|
|
# pragma once
|
|
|
|
# include <openssl/macros.h>
|
|
# ifndef OPENSSL_NO_DEPRECATED_3_0
|
|
# define HEADER_RAND_H
|
|
# endif
|
|
|
|
# include <stdlib.h>
|
|
# include <openssl/types.h>
|
|
# include <openssl/e_os2.h>
|
|
# include <openssl/randerr.h>
|
|
# include <openssl/evp.h>
|
|
|
|
#ifdef __cplusplus
|
|
extern "C" {
|
|
#endif
|
|
|
|
/*
|
|
* Default security strength (in the sense of [NIST SP 800-90Ar1])
|
|
*
|
|
* NIST SP 800-90Ar1 supports the strength of the DRBG being smaller than that
|
|
* of the cipher by collecting less entropy. The current DRBG implementation
|
|
* does not take RAND_DRBG_STRENGTH into account and sets the strength of the
|
|
* DRBG to that of the cipher.
|
|
*/
|
|
# define RAND_DRBG_STRENGTH 256
|
|
|
|
# ifndef OPENSSL_NO_DEPRECATED_3_0
|
|
struct rand_meth_st {
|
|
int (*seed) (const void *buf, int num);
|
|
int (*bytes) (unsigned char *buf, int num);
|
|
void (*cleanup) (void);
|
|
int (*add) (const void *buf, int num, double randomness);
|
|
int (*pseudorand) (unsigned char *buf, int num);
|
|
int (*status) (void);
|
|
};
|
|
|
|
OSSL_DEPRECATEDIN_3_0 int RAND_set_rand_method(const RAND_METHOD *meth);
|
|
OSSL_DEPRECATEDIN_3_0 const RAND_METHOD *RAND_get_rand_method(void);
|
|
# ifndef OPENSSL_NO_ENGINE
|
|
OSSL_DEPRECATEDIN_3_0 int RAND_set_rand_engine(ENGINE *engine);
|
|
# endif
|
|
|
|
OSSL_DEPRECATEDIN_3_0 RAND_METHOD *RAND_OpenSSL(void);
|
|
# endif /* OPENSSL_NO_DEPRECATED_3_0 */
|
|
|
|
# ifndef OPENSSL_NO_DEPRECATED_1_1_0
|
|
# define RAND_cleanup() while(0) continue
|
|
# endif
|
|
int RAND_bytes(unsigned char *buf, int num);
|
|
int RAND_priv_bytes(unsigned char *buf, int num);
|
|
|
|
/*
|
|
* Equivalent of RAND_priv_bytes() but additionally taking an OSSL_LIB_CTX and
|
|
* a strength.
|
|
*/
|
|
int RAND_priv_bytes_ex(OSSL_LIB_CTX *ctx, unsigned char *buf, size_t num,
|
|
unsigned int strength);
|
|
|
|
/*
|
|
* Equivalent of RAND_bytes() but additionally taking an OSSL_LIB_CTX and
|
|
* a strength.
|
|
*/
|
|
int RAND_bytes_ex(OSSL_LIB_CTX *ctx, unsigned char *buf, size_t num,
|
|
unsigned int strength);
|
|
|
|
# ifndef OPENSSL_NO_DEPRECATED_1_1_0
|
|
OSSL_DEPRECATEDIN_1_1_0 int RAND_pseudo_bytes(unsigned char *buf, int num);
|
|
# endif
|
|
|
|
EVP_RAND_CTX *RAND_get0_primary(OSSL_LIB_CTX *ctx);
|
|
EVP_RAND_CTX *RAND_get0_public(OSSL_LIB_CTX *ctx);
|
|
EVP_RAND_CTX *RAND_get0_private(OSSL_LIB_CTX *ctx);
|
|
|
|
int RAND_set_DRBG_type(OSSL_LIB_CTX *ctx, const char *drbg, const char *propq,
|
|
const char *cipher, const char *digest);
|
|
int RAND_set_seed_source_type(OSSL_LIB_CTX *ctx, const char *seed,
|
|
const char *propq);
|
|
|
|
void RAND_seed(const void *buf, int num);
|
|
void RAND_keep_random_devices_open(int keep);
|
|
|
|
# if defined(__ANDROID__) && defined(__NDK_FPABI__)
|
|
__NDK_FPABI__ /* __attribute__((pcs("aapcs"))) on ARM */
|
|
# endif
|
|
void RAND_add(const void *buf, int num, double randomness);
|
|
int RAND_load_file(const char *file, long max_bytes);
|
|
int RAND_write_file(const char *file);
|
|
const char *RAND_file_name(char *file, size_t num);
|
|
int RAND_status(void);
|
|
|
|
# ifndef OPENSSL_NO_EGD
|
|
int RAND_query_egd_bytes(const char *path, unsigned char *buf, int bytes);
|
|
int RAND_egd(const char *path);
|
|
int RAND_egd_bytes(const char *path, int bytes);
|
|
# endif
|
|
|
|
int RAND_poll(void);
|
|
|
|
# if defined(_WIN32) && (defined(BASETYPES) || defined(_WINDEF_H))
|
|
/* application has to include <windows.h> in order to use these */
|
|
# ifndef OPENSSL_NO_DEPRECATED_1_1_0
|
|
OSSL_DEPRECATEDIN_1_1_0 void RAND_screen(void);
|
|
OSSL_DEPRECATEDIN_1_1_0 int RAND_event(UINT, WPARAM, LPARAM);
|
|
# endif
|
|
# endif
|
|
|
|
#ifdef __cplusplus
|
|
}
|
|
#endif
|
|
|
|
#endif
|