[source] mbedtls: sync with polarssl config

LEDE Commits lede-commits at lists.infradead.org
Mon Dec 12 01:23:55 PST 2016


nbd pushed a commit to source.git, branch master:
https://git.lede-project.org/732c24a0cac4293b058c99ff7867fd13a2670eca

commit 732c24a0cac4293b058c99ff7867fd13a2670eca
Author: Felix Fietkau <nbd at nbd.name>
AuthorDate: Sat Dec 10 11:22:58 2016 +0100

    mbedtls: sync with polarssl config
    
    One of those changes is re-enabling blowfish support to make
    openvpn-mbedtls compatible with common configurations
    
    Signed-off-by: Felix Fietkau <nbd at nbd.name>
---
 package/libs/mbedtls/patches/200-config.patch | 89 ++++++++++++++++++++++++---
 1 file changed, 80 insertions(+), 9 deletions(-)

diff --git a/package/libs/mbedtls/patches/200-config.patch b/package/libs/mbedtls/patches/200-config.patch
index 75d8342..9e477ef 100644
--- a/package/libs/mbedtls/patches/200-config.patch
+++ b/package/libs/mbedtls/patches/200-config.patch
@@ -36,6 +36,16 @@
  #define MBEDTLS_ECP_DP_SECP256K1_ENABLED
  #define MBEDTLS_ECP_DP_BP256R1_ENABLED
  #define MBEDTLS_ECP_DP_BP384R1_ENABLED
+@@ -476,8 +476,8 @@
+  * Requires: MBEDTLS_HMAC_DRBG_C
+  *
+  * Comment this macro to disable deterministic ECDSA.
+- */
+ #define MBEDTLS_ECDSA_DETERMINISTIC
++ */
+ 
+ /**
+  * \def MBEDTLS_KEY_EXCHANGE_PSK_ENABLED
 @@ -523,7 +523,7 @@
   *      MBEDTLS_TLS_DHE_PSK_WITH_3DES_EDE_CBC_SHA
   *      MBEDTLS_TLS_DHE_PSK_WITH_RC4_128_SHA
@@ -45,6 +55,16 @@
  
  /**
   * \def MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED
+@@ -542,8 +542,8 @@
+  *      MBEDTLS_TLS_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256
+  *      MBEDTLS_TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA
+  *      MBEDTLS_TLS_ECDHE_PSK_WITH_RC4_128_SHA
+- */
+ #define MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED
++ */
+ 
+ /**
+  * \def MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED
 @@ -568,7 +568,7 @@
   *      MBEDTLS_TLS_RSA_PSK_WITH_3DES_EDE_CBC_SHA
   *      MBEDTLS_TLS_RSA_PSK_WITH_RC4_128_SHA
@@ -116,6 +136,16 @@
  
  /**
   * \def MBEDTLS_SSL_ALL_ALERT_MESSAGES
+@@ -1234,8 +1234,8 @@
+  * callbacks are provided by MBEDTLS_SSL_TICKET_C.
+  *
+  * Comment this macro to disable support for SSL session tickets
+- */
+ #define MBEDTLS_SSL_SESSION_TICKETS
++ */
+ 
+ /**
+  * \def MBEDTLS_SSL_EXPORT_KEYS
 @@ -1265,7 +1265,7 @@
   *
   * Comment this macro to disable support for truncated HMAC in SSL
@@ -125,6 +155,16 @@
  
  /**
   * \def MBEDTLS_THREADING_ALT
+@@ -1299,8 +1299,8 @@
+  * Requires: MBEDTLS_VERSION_C
+  *
+  * Comment this to disable run-time checking and save ROM space
+- */
+ #define MBEDTLS_VERSION_FEATURES
++ */
+ 
+ /**
+  * \def MBEDTLS_X509_ALLOW_EXTENSIONS_NON_V3
 @@ -1501,7 +1501,7 @@
   *      MBEDTLS_TLS_RSA_PSK_WITH_RC4_128_SHA
   *      MBEDTLS_TLS_PSK_WITH_RC4_128_SHA
@@ -134,15 +174,6 @@
  
  /**
   * \def MBEDTLS_ASN1_PARSE_C
-@@ -1566,7 +1566,7 @@
-  *
-  * Module:  library/blowfish.c
-  */
--#define MBEDTLS_BLOWFISH_C
-+//#define MBEDTLS_BLOWFISH_C
- 
- /**
-  * \def MBEDTLS_CAMELLIA_C
 @@ -1621,7 +1621,7 @@
   *      MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_GCM_SHA256
   *      MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_CBC_SHA256
@@ -179,6 +210,16 @@
  
  /**
   * \def MBEDTLS_DES_C
+@@ -1880,8 +1880,8 @@
+  * Requires: MBEDTLS_MD_C
+  *
+  * Uncomment to enable the HMAC_DRBG random number geerator.
+- */
+ #define MBEDTLS_HMAC_DRBG_C
++ */
+ 
+ /**
+  * \def MBEDTLS_MD_C
 @@ -2158,7 +2158,7 @@
   * Caller:  library/mbedtls_md.c
   *
@@ -188,6 +229,36 @@
  
  /**
   * \def MBEDTLS_RSA_C
+@@ -2235,8 +2235,8 @@
+  * Caller:
+  *
+  * Requires: MBEDTLS_SSL_CACHE_C
+- */
+ #define MBEDTLS_SSL_CACHE_C
++ */
+ 
+ /**
+  * \def MBEDTLS_SSL_COOKIE_C
+@@ -2257,8 +2257,8 @@
+  * Caller:
+  *
+  * Requires: MBEDTLS_CIPHER_C
+- */
+ #define MBEDTLS_SSL_TICKET_C
++ */
+ 
+ /**
+  * \def MBEDTLS_SSL_CLI_C
+@@ -2357,8 +2357,8 @@
+  * Module:  library/version.c
+  *
+  * This module provides run-time version information.
+- */
+ #define MBEDTLS_VERSION_C
++ */
+ 
+ /**
+  * \def MBEDTLS_X509_USE_C
 @@ -2468,7 +2468,7 @@
   * Module:  library/xtea.c
   * Caller:



More information about the lede-commits mailing list