acvp: don't include CMAC-AES in regcap dump.

CMAC-AES isn't inside our FIPS module, it's only included in
modulewrapper in order to test acvptool. Mark it with a special tag to
avoid it appearing when dumping regcap JSON because NIST paperwork is
such that it's better not to ACVP test such code.

Change-Id: I0c6d3a38bce9bf5766b889677eb3f7de94262c24
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/45465
Reviewed-by: David Benjamin <davidben@google.com>
This commit is contained in:
Adam Langley
2021-02-09 22:57:26 +00:00
parent 4d3e540cc0
commit fc23300164
2 changed files with 16 additions and 1 deletions
+15 -1
View File
@@ -279,9 +279,23 @@ func main() {
}
if *dumpRegcap {
nonTestAlgos := make([]map[string]interface{}, 0, len(supportedAlgos))
for _, algo := range supportedAlgos {
if value, ok := algo["acvptoolTestOnly"]; ok {
testOnly, ok := value.(bool)
if !ok {
log.Fatalf("modulewrapper config contains acvptoolTestOnly field with non-boolean value %#v", value)
}
if testOnly {
continue
}
}
nonTestAlgos = append(nonTestAlgos, algo)
}
regcap := []map[string]interface{}{
map[string]interface{}{"acvVersion": "1.0"},
map[string]interface{}{"algorithms": supportedAlgos},
map[string]interface{}{"algorithms": nonTestAlgos},
}
regcapBytes, err := json.MarshalIndent(regcap, "", " ")
if err != nil {
@@ -676,6 +676,7 @@ static bool GetConfig(const Span<const uint8_t> args[]) {
},
{
"algorithm": "CMAC-AES",
"acvptoolTestOnly": true,
"revision": "1.0",
"capabilities": [{
"direction": ["gen", "ver"],