|
|
8b87dc |
diff -up aide-0.15.1/src/aide.c.fipsfix aide-0.15.1/src/aide.c
|
|
|
8b87dc |
--- aide-0.15.1/src/aide.c.fipsfix 2010-08-08 19:39:31.000000000 +0200
|
|
|
8b87dc |
+++ aide-0.15.1/src/aide.c 2012-11-22 16:59:45.378713818 +0100
|
|
|
8b87dc |
@@ -484,9 +484,28 @@ int main(int argc,char**argv)
|
|
|
8b87dc |
#endif
|
|
|
8b87dc |
umask(0177);
|
|
|
8b87dc |
init_sighandler();
|
|
|
8b87dc |
-
|
|
|
8b87dc |
setdefaults_before_config();
|
|
|
8b87dc |
|
|
|
8b87dc |
+#if WITH_GCRYPT
|
|
|
8b87dc |
+ error(255,"Gcrypt library initialization\n");
|
|
|
8b87dc |
+ /*
|
|
|
8b87dc |
+ * Initialize libgcrypt as per
|
|
|
8b87dc |
+ * http://www.gnupg.org/documentation/manuals/gcrypt/Initializing-the-library.html
|
|
|
8b87dc |
+ *
|
|
|
8b87dc |
+ *
|
|
|
8b87dc |
+ */
|
|
|
8b87dc |
+ gcry_control(GCRYCTL_SET_ENFORCED_FIPS_FLAG, 0);
|
|
|
8b87dc |
+ gcry_control(GCRYCTL_INIT_SECMEM, 1);
|
|
|
8b87dc |
+
|
|
|
8b87dc |
+ if(!gcry_check_version(GCRYPT_VERSION)) {
|
|
|
8b87dc |
+ error(0,"libgcrypt version mismatch\n");
|
|
|
8b87dc |
+ exit(VERSION_MISMATCH_ERROR);
|
|
|
8b87dc |
+ }
|
|
|
8b87dc |
+
|
|
|
8b87dc |
+ gcry_control(GCRYCTL_INITIALIZATION_FINISHED, 0);
|
|
|
8b87dc |
+#endif /* WITH_GCRYPT */
|
|
|
8b87dc |
+
|
|
|
8b87dc |
+
|
|
|
8b87dc |
if(read_param(argc,argv)==RETFAIL){
|
|
|
8b87dc |
error(0, _("Invalid argument\n") );
|
|
|
8b87dc |
exit(INVALID_ARGUMENT_ERROR);
|
|
|
8b87dc |
@@ -641,6 +660,9 @@ int main(int argc,char**argv)
|
|
|
8b87dc |
}
|
|
|
8b87dc |
#endif
|
|
|
8b87dc |
}
|
|
|
8b87dc |
+#ifdef WITH_GCRYPT
|
|
|
8b87dc |
+ gcry_control(GCRYCTL_TERM_SECMEM, 0);
|
|
|
8b87dc |
+#endif /* WITH_GCRYPT */
|
|
|
8b87dc |
return RETOK;
|
|
|
8b87dc |
}
|
|
|
8b87dc |
const char* aide_key_3=CONFHMACKEY_03;
|
|
|
8b87dc |
diff -up aide-0.15.1/src/md.c.fipsfix aide-0.15.1/src/md.c
|
|
|
8b87dc |
--- aide-0.15.1/src/md.c.fipsfix 2010-08-08 19:39:31.000000000 +0200
|
|
|
8b87dc |
+++ aide-0.15.1/src/md.c 2012-11-22 16:59:33.166673632 +0100
|
|
|
8b87dc |
@@ -201,14 +201,7 @@ int init_md(struct md_container* md) {
|
|
|
8b87dc |
}
|
|
|
8b87dc |
#endif
|
|
|
8b87dc |
#ifdef WITH_GCRYPT
|
|
|
8b87dc |
- error(255,"Gcrypt library initialization\n");
|
|
|
8b87dc |
- if(!gcry_check_version(GCRYPT_VERSION)) {
|
|
|
8b87dc |
- error(0,"libgcrypt version mismatch\n");
|
|
|
8b87dc |
- exit(VERSION_MISMATCH_ERROR);
|
|
|
8b87dc |
- }
|
|
|
8b87dc |
- gcry_control(GCRYCTL_DISABLE_SECMEM, 0);
|
|
|
8b87dc |
- gcry_control(GCRYCTL_INITIALIZATION_FINISHED, 0);
|
|
|
8b87dc |
- if(gcry_md_open(&md->mdh,0,0)!=GPG_ERR_NO_ERROR){
|
|
|
8b87dc |
+ if(gcry_md_open(&md->mdh,0,GCRY_MD_FLAG_SECURE)!=GPG_ERR_NO_ERROR){
|
|
|
8b87dc |
error(0,"gcrypt_md_open failed\n");
|
|
|
8b87dc |
exit(IO_ERROR);
|
|
|
8b87dc |
}
|
|
|
8b87dc |
@@ -299,7 +292,7 @@ int close_md(struct md_container* md) {
|
|
|
8b87dc |
|
|
|
8b87dc |
/*. There might be more hashes in the library. Add those here.. */
|
|
|
8b87dc |
|
|
|
8b87dc |
- gcry_md_reset(md->mdh);
|
|
|
8b87dc |
+ gcry_md_close(md->mdh);
|
|
|
8b87dc |
#endif
|
|
|
8b87dc |
|
|
|
8b87dc |
#ifdef WITH_MHASH
|
|
|
8b87dc |
diff -up aide-0.15.1/src/util.c.fipsfix aide-0.15.1/src/util.c
|
|
|
8b87dc |
--- aide-0.15.1/src/util.c.fipsfix 2010-08-08 19:39:31.000000000 +0200
|
|
|
8b87dc |
+++ aide-0.15.1/src/util.c 2012-11-22 16:59:33.166673632 +0100
|
|
|
8b87dc |
@@ -494,28 +494,5 @@ int syslog_facility_lookup(char *s)
|
|
|
8b87dc |
return(AIDE_SYSLOG_FACILITY);
|
|
|
8b87dc |
}
|
|
|
8b87dc |
|
|
|
8b87dc |
-/* We need these dummy stubs to fool the linker into believing that
|
|
|
8b87dc |
- we do not need them at link time */
|
|
|
8b87dc |
-
|
|
|
8b87dc |
-void* dlopen(char*filename,int flag)
|
|
|
8b87dc |
-{
|
|
|
8b87dc |
- return NULL;
|
|
|
8b87dc |
-}
|
|
|
8b87dc |
-
|
|
|
8b87dc |
-void* dlsym(void*handle,char*symbol)
|
|
|
8b87dc |
-{
|
|
|
8b87dc |
- return NULL;
|
|
|
8b87dc |
-}
|
|
|
8b87dc |
-
|
|
|
8b87dc |
-void* dlclose(void*handle)
|
|
|
8b87dc |
-{
|
|
|
8b87dc |
- return NULL;
|
|
|
8b87dc |
-}
|
|
|
8b87dc |
-
|
|
|
8b87dc |
-const char* dlerror(void)
|
|
|
8b87dc |
-{
|
|
|
8b87dc |
- return NULL;
|
|
|
8b87dc |
-}
|
|
|
8b87dc |
-
|
|
|
8b87dc |
const char* aide_key_2=CONFHMACKEY_02;
|
|
|
8b87dc |
const char* db_key_2=DBHMACKEY_02;
|