diff --git a/util/fipstools/acvp/acvptool/acvp.go b/util/fipstools/acvp/acvptool/acvp.go index df627cc74..87c2f8741 100644 --- a/util/fipstools/acvp/acvptool/acvp.go +++ b/util/fipstools/acvp/acvptool/acvp.go @@ -279,9 +279,23 @@ func main() { } if *dumpRegcap { + nonTestAlgos := make([]map[string]interface{}, 0, len(supportedAlgos)) + for _, algo := range supportedAlgos { + if value, ok := algo["acvptoolTestOnly"]; ok { + testOnly, ok := value.(bool) + if !ok { + log.Fatalf("modulewrapper config contains acvptoolTestOnly field with non-boolean value %#v", value) + } + if testOnly { + continue + } + } + nonTestAlgos = append(nonTestAlgos, algo) + } + regcap := []map[string]interface{}{ map[string]interface{}{"acvVersion": "1.0"}, - map[string]interface{}{"algorithms": supportedAlgos}, + map[string]interface{}{"algorithms": nonTestAlgos}, } regcapBytes, err := json.MarshalIndent(regcap, "", " ") if err != nil { diff --git a/util/fipstools/acvp/modulewrapper/modulewrapper.cc b/util/fipstools/acvp/modulewrapper/modulewrapper.cc index b35428058..a08e670d6 100644 --- a/util/fipstools/acvp/modulewrapper/modulewrapper.cc +++ b/util/fipstools/acvp/modulewrapper/modulewrapper.cc @@ -676,6 +676,7 @@ static bool GetConfig(const Span args[]) { }, { "algorithm": "CMAC-AES", + "acvptoolTestOnly": true, "revision": "1.0", "capabilities": [{ "direction": ["gen", "ver"],