From 613a5e18e4e3b906c1ab64afb4a451c0bd187759 Mon Sep 17 00:00:00 2001 From: Kai Engert Date: Wed, 7 Nov 2007 00:37:19 +0000 Subject: [PATCH] - NSS 3.12 alpha 2 --- .cvsignore | 6 +- fake-kstat.h | 20 - nss-3.11-zdefs.patch | 16 - nss-bug180726.patch | 11 - nss-create-obj.patch | 28 +- nss-decouple-softokn.patch | 317 -------- nss-disable-build-freebl-softoken.patch | 386 ---------- nss-limit-suite-b.patch | 916 ------------------------ nss-smartcard-auth.patch | 83 --- nss-use-netstat-hack.patch | 11 - nss.spec | 112 +-- sources | 6 +- 12 files changed, 38 insertions(+), 1874 deletions(-) delete mode 100644 fake-kstat.h delete mode 100644 nss-3.11-zdefs.patch delete mode 100644 nss-bug180726.patch delete mode 100644 nss-decouple-softokn.patch delete mode 100644 nss-disable-build-freebl-softoken.patch delete mode 100644 nss-limit-suite-b.patch delete mode 100644 nss-smartcard-auth.patch delete mode 100644 nss-use-netstat-hack.patch diff --git a/.cvsignore b/.cvsignore index 6277b7e..40b28e3 100644 --- a/.cvsignore +++ b/.cvsignore @@ -1,4 +1,2 @@ -nss-3.11.5-fbst-stripped.tar.gz -nss-3.11.7-no-fbst-with-ckbi-1.64.tar.gz -nss-3.12-alpha-ckfw.tar.gz -nss-3.12-alpha-pem.tar.gz +nss-3.11.99.2-stripped.tar.bz2 +nss-pem.tar.gz diff --git a/fake-kstat.h b/fake-kstat.h deleted file mode 100644 index 8d7026b..0000000 --- a/fake-kstat.h +++ /dev/null @@ -1,20 +0,0 @@ -struct tag_kstat_t -{ - struct tag_kstat_t *ks_next; - char* ks_data; - PRUint32 ks_data_size; - int ks_ndata; -}; - -struct tag_kstat_ctl_t -{ - struct tag_kstat_t *kc_chain; -}; - -typedef struct tag_kstat_t kstat_t; -typedef struct tag_kstat_ctl_t kstat_ctl_t; - -#define kstat_open() NULL -#define kstat_read(a,b,c) -1 -#define kstat_close(x) -1 - diff --git a/nss-3.11-zdefs.patch b/nss-3.11-zdefs.patch deleted file mode 100644 index 0e8128c..0000000 --- a/nss-3.11-zdefs.patch +++ /dev/null @@ -1,16 +0,0 @@ -Index: mozilla/security/coreconf/Linux.mk -=================================================================== -RCS file: /cvsroot/mozilla/security/coreconf/Linux.mk,v -retrieving revision 1.27 -diff -u -r1.27 Linux.mk ---- mozilla/security/coreconf/Linux.mk 16 Sep 2005 17:09:23 -0000 1.27 -+++ mozilla/security/coreconf/Linux.mk 15 Dec 2005 21:25:00 -0000 -@@ -165,7 +165,7 @@ - ARCH = linux - - DSO_CFLAGS = -fPIC --DSO_LDOPTS = -shared $(ARCHFLAG) -z defs -+DSO_LDOPTS = -shared $(ARCHFLAG) -Wl,-z,defs - DSO_LDFLAGS = - LDFLAGS += $(ARCHFLAG) - diff --git a/nss-bug180726.patch b/nss-bug180726.patch deleted file mode 100644 index 6462914..0000000 --- a/nss-bug180726.patch +++ /dev/null @@ -1,11 +0,0 @@ ---- mozilla/security/nss/lib/freebl/Makefile.fix180726 2006-02-15 07:19:21.000000000 +0100 -+++ mozilla/security/nss/lib/freebl/Makefile 2006-02-15 07:19:25.000000000 +0100 -@@ -134,7 +134,7 @@ - ifeq ($(OS_TARGET),Linux) - ifeq ($(CPU_ARCH),x86_64) - ASFILES = arcfour-amd64-gas.s mpi_amd64_gas.s -- ASFLAGS += -march=opteron -m64 -fPIC -+ ASFLAGS += -march=opteron -m64 -fPIC -Wa,--noexecstack - DEFINES += -DNSS_BEVAND_ARCFOUR -DMPI_AMD64 -DMP_ASSEMBLY_MULTIPLY - DEFINES += -DNSS_USE_COMBA - MPI_SRCS += mpi_amd64.c mp_comba.c diff --git a/nss-create-obj.patch b/nss-create-obj.patch index abac4fc..537e9a1 100644 --- a/nss-create-obj.patch +++ b/nss-create-obj.patch @@ -1,21 +1,17 @@ -Index: mozilla/security/nss/lib/nss/nss.def -=================================================================== -RCS file: /cvsroot/mozilla/security/nss/lib/nss/nss.def,v -retrieving revision 1.158.2.7 -diff -u -r1.158.2.7 nss.def ---- mozilla/security/nss/lib/nss/nss.def 25 Apr 2007 23:26:53 -0000 1.158.2.7 -+++ mozilla/security/nss/lib/nss/nss.def 31 Aug 2007 18:54:54 -0000 -@@ -899,3 +899,10 @@ - ;+ local: - ;+ *; - ;+}; -+;+NSS_3.12 { -+;+ global: +diff -up mozilla/security/nss/lib/nss/nss.def.createobj mozilla/security/nss/lib/nss/nss.def +--- mozilla/security/nss/lib/nss/nss.def.createobj 2007-11-06 14:11:40.000000000 +0100 ++++ mozilla/security/nss/lib/nss/nss.def 2007-11-06 14:11:59.000000000 +0100 +@@ -913,8 +913,10 @@ CERT_FindCRLEntryReasonExten; + CERT_FindCRLNumberExten; + CERT_FindNameConstraintsExten; + CERT_PKIXVerifyCert; +PK11_CreateGenericObject; + PK11_GenerateKeyPairWithOpFlags; + PK11_GetAllSlotsForCert; +PK11_WriteRawAttribute; -+;+ local: -+;+ *; -+;+}; + SECKEY_ECParamsToBasePointOrderLen; + SECKEY_ECParamsToKeySize; + SECMOD_DeleteModuleEx; Index: mozilla/security/nss/lib/pk11wrap/pk11obj.c =================================================================== RCS file: /cvsroot/mozilla/security/nss/lib/pk11wrap/pk11obj.c,v diff --git a/nss-decouple-softokn.patch b/nss-decouple-softokn.patch deleted file mode 100644 index ae0d535..0000000 --- a/nss-decouple-softokn.patch +++ /dev/null @@ -1,317 +0,0 @@ -? mozilla/security/nss/cmd/crmf-cgi/~Makefile -? mozilla/security/nss/lib/ckfw/builtins/qa.der -Index: mozilla/security/nss/lib/nss/config.mk -=================================================================== -RCS file: /cvsroot/mozilla/security/nss/lib/nss/config.mk,v -retrieving revision 1.26.2.1 -diff -u -p -r1.26.2.1 config.mk ---- mozilla/security/nss/lib/nss/config.mk 17 Nov 2006 01:33:15 -0000 1.26.2.1 -+++ mozilla/security/nss/lib/nss/config.mk 12 Jun 2007 01:29:35 -0000 -@@ -53,7 +53,6 @@ RESNAME = $(LIBRARY_NAME).rc - ifdef NS_USE_GCC - EXTRA_SHARED_LIBS += \ - -L$(DIST)/lib \ -- -lsoftokn3 \ - -L$(NSPR_LIB_DIR) \ - -lplc4 \ - -lplds4 \ -@@ -61,7 +60,6 @@ EXTRA_SHARED_LIBS += \ - $(NULL) - else # ! NS_USE_GCC - EXTRA_SHARED_LIBS += \ -- $(DIST)/lib/softokn3.lib \ - $(NSPR_LIB_DIR)/$(NSPR31_LIB_PREFIX)plc4.lib \ - $(NSPR_LIB_DIR)/$(NSPR31_LIB_PREFIX)plds4.lib \ - $(NSPR_LIB_DIR)/$(NSPR31_LIB_PREFIX)nspr4.lib \ -@@ -74,7 +72,6 @@ else - # $(EXTRA_SHARED_LIBS) come before $(OS_LIBS), except on AIX. - EXTRA_SHARED_LIBS += \ - -L$(DIST)/lib \ -- -lsoftokn3 \ - -L$(NSPR_LIB_DIR) \ - -lplc4 \ - -lplds4 \ -Index: mozilla/security/nss/lib/pk11wrap/manifest.mn -=================================================================== -RCS file: /cvsroot/mozilla/security/nss/lib/pk11wrap/manifest.mn,v -retrieving revision 1.16.2.1 -diff -u -p -r1.16.2.1 manifest.mn ---- mozilla/security/nss/lib/pk11wrap/manifest.mn 2 Jun 2007 02:23:37 -0000 1.16.2.1 -+++ mozilla/security/nss/lib/pk11wrap/manifest.mn 12 Jun 2007 01:29:35 -0000 -@@ -82,6 +82,13 @@ REQUIRES = dbm - - LIBRARY_NAME = pk11wrap - -+LIBRARY_VERSION = 3 -+SOFTOKEN_LIBRARY_VERSION = 3 -+ -+DEFINES += -DSHLIB_SUFFIX=\"$(DLL_SUFFIX)\" -DSHLIB_PREFIX=\"$(DLL_PREFIX)\" \ -+ -DSHLIB_VERSION=\"$(LIBRARY_VERSION)\" \ -+ -DSOFTOKEN_SHLIB_VERSION=\"$(SOFTOKEN_LIBRARY_VERSION)\" -+ - # only add module debugging in opt builds if DEBUG_PKCS11 is set - ifdef DEBUG_PKCS11 - DEFINES += -DDEBUG_MODULE -DFORCE_PR_LOG -Index: mozilla/security/nss/lib/pk11wrap/pk11load.c -=================================================================== -RCS file: /cvsroot/mozilla/security/nss/lib/pk11wrap/pk11load.c,v -retrieving revision 1.17 -diff -u -p -r1.17 pk11load.c ---- mozilla/security/nss/lib/pk11wrap/pk11load.c 20 Sep 2005 20:56:07 -0000 1.17 -+++ mozilla/security/nss/lib/pk11wrap/pk11load.c 12 Jun 2007 01:29:35 -0000 -@@ -47,10 +47,6 @@ - #include "nssilock.h" - #include "secerr.h" - --extern void FC_GetFunctionList(void); --extern void NSC_GetFunctionList(void); --extern void NSC_ModuleDBFunc(void); -- - #ifdef DEBUG - #define DEBUG_MODULE 1 - #endif -@@ -221,6 +217,196 @@ SECMOD_SetRootCerts(PK11SlotInfo *slot, - } - } - -+static const char* nss_name = -+ SHLIB_PREFIX"nss"SHLIB_VERSION"."SHLIB_SUFFIX; -+static const char* softoken_default_name = -+ SHLIB_PREFIX"softokn"SOFTOKEN_SHLIB_VERSION"."SHLIB_SUFFIX; -+static PRCallOnceType loadSoftokenOnce; -+static PRLibrary* softokenLib; -+ -+#ifdef XP_UNIX -+#include -+#define BL_MAXSYMLINKS 20 -+ -+/* ### Copied from freebl/loader.c and freebl changed to softoken. */ -+/* -+ * If 'link' is a symbolic link, this function follows the symbolic links -+ * and returns the pathname of the ultimate source of the symbolic links. -+ * If 'link' is not a symbolic link, this function returns NULL. -+ * The caller should call PR_Free to free the string returned by this -+ * function. -+ */ -+static char* st_GetOriginalPathname(const char* link) -+{ -+ char* resolved = NULL; -+ char* input = NULL; -+ PRUint32 iterations = 0; -+ PRInt32 len = 0, retlen = 0; -+ if (!link) { -+ PR_SetError(PR_INVALID_ARGUMENT_ERROR, 0); -+ return NULL; -+ } -+ len = PR_MAX(1024, strlen(link) + 1); -+ resolved = PR_Malloc(len); -+ input = PR_Malloc(len); -+ if (!resolved || !input) { -+ if (resolved) { -+ PR_Free(resolved); -+ } -+ if (input) { -+ PR_Free(input); -+ } -+ return NULL; -+ } -+ strcpy(input, link); -+ while ( (iterations++ < BL_MAXSYMLINKS) && -+ ( (retlen = readlink(input, resolved, len - 1)) > 0) ) { -+ char* tmp = input; -+ resolved[retlen] = '\0'; /* NULL termination */ -+ input = resolved; -+ resolved = tmp; -+ } -+ PR_Free(resolved); -+ if (iterations == 1 && retlen < 0) { -+ PR_Free(input); -+ input = NULL; -+ } -+ return input; -+} -+#endif /* XP_UNIX */ -+ -+/* -+ * We use PR_GetLibraryFilePathname to get the pathname of the loaded -+ * shared lib that contains this function, and then do a PR_LoadLibrary -+ * with an absolute pathname for the softoken shared library. -+ */ -+ -+#include "prio.h" -+#include "prprf.h" -+#include -+#include "prsystem.h" -+ -+/* ### Copied from freebl/loader.c and freebl changed to softoken, -+ * and softoken changed to nss. -+ */ -+/* -+ * Load the softoken library with the file name 'name' residing in the same -+ * directory as libnss, whose pathname is 'nssPath'. -+ */ -+static PRLibrary * -+st_LoadSoftokenLibInNssDir(const char *nssPath, const char *name) -+{ -+ PRLibrary *dlh = NULL; -+ char *fullName = NULL; -+ char* c; -+ PRLibSpec libSpec; -+ -+ /* Remove "libnss" from the pathname and add the softoken libname */ -+ c = strrchr(nssPath, PR_GetDirectorySeparator()); -+ if (c) { -+ size_t nssPathSize = 1 + c - nssPath; -+ fullName = (char*) PORT_Alloc(strlen(name) + nssPathSize + 1); -+ if (fullName) { -+ memcpy(fullName, nssPath, nssPathSize); -+ strcpy(fullName + nssPathSize, name); -+#ifdef DEBUG_LOADER -+ PR_fprintf(PR_STDOUT, "\nAttempting to load fully-qualified %s\n", -+ fullName); -+#endif -+ libSpec.type = PR_LibSpec_Pathname; -+ libSpec.value.pathname = fullName; -+ dlh = PR_LoadLibraryWithFlags(libSpec, PR_LD_NOW | PR_LD_LOCAL); -+ PORT_Free(fullName); -+ } -+ } -+ return dlh; -+} -+ -+/* ### Copied from freebl/loader.c and freebl changed to softoken, -+ * and softoken changed to nss. -+ */ -+static PRLibrary * -+st_LoadLibrary(const char *name) -+{ -+ PRLibrary *lib = NULL; -+ PRFuncPtr fn_addr; -+ char* nssPath = NULL; -+ PRLibSpec libSpec; -+ -+ /* Get the pathname for the loaded libnss, i.e. /usr/lib/libnss3.so -+ * PR_GetLibraryFilePathname works with either the base library name or a -+ * function pointer, depending on the platform. We can't query an exported -+ * symbol such as NSC_GetFunctionList, because on some platforms we can't -+ * find symbols in loaded implicit dependencies such as libnss. -+ * But we can just get the address of this function ! -+ */ -+ fn_addr = (PRFuncPtr) &st_LoadLibrary; -+ nssPath = PR_GetLibraryFilePathname(nss_name, fn_addr); -+ -+ if (nssPath) { -+ lib = st_LoadSoftokenLibInNssDir(nssPath, name); -+#ifdef XP_UNIX -+ if (!lib) { -+ /* -+ * If nssPath is a symbolic link, resolve the symbolic -+ * link and try again. -+ */ -+ char* originalNssPath = st_GetOriginalPathname(nssPath); -+ if (originalNssPath) { -+ PR_Free(nssPath); -+ nssPath = originalNssPath; -+ lib = st_LoadSoftokenLibInNssDir(nssPath, name); -+ } -+ } -+#endif -+ PR_Free(nssPath); -+ } -+ if (!lib) { -+#ifdef DEBUG_LOADER -+ PR_fprintf(PR_STDOUT, "\nAttempting to load %s\n", name); -+#endif -+ libSpec.type = PR_LibSpec_Pathname; -+ libSpec.value.pathname = name; -+ lib = PR_LoadLibraryWithFlags(libSpec, PR_LD_NOW | PR_LD_LOCAL); -+ } -+ if (NULL == lib) { -+#ifdef DEBUG_LOADER -+ PR_fprintf(PR_STDOUT, "\nLoading failed : %s.\n", name); -+#endif -+ } -+ return lib; -+} -+ -+/* This function must be run only once. */ -+/* determine if hybrid platform, then actually load the DSO. */ -+static PRStatus -+softoken_LoadDSO( void ) -+{ -+ PRLibrary * handle; -+ const char * name = softoken_default_name; -+ -+ if (!name) { -+ PR_SetError(PR_LOAD_LIBRARY_ERROR, 0); -+ return PR_FAILURE; -+ } -+ -+ handle = st_LoadLibrary(name); -+ if (handle) { -+ softokenLib = handle; -+ return PR_SUCCESS; -+ } -+ return PR_FAILURE; -+} -+ -+static PRStatus -+softoken_RunLoaderOnce( void ) -+{ -+ PRStatus status; -+ -+ status = PR_CallOnce(&loadSoftokenOnce, &softoken_LoadDSO); -+ return status; -+} -+ - /* - * load a new module into our address space and initialize it. - */ -@@ -238,6 +424,11 @@ SECMOD_LoadPKCS11Module(SECMODModule *mo - - /* intenal modules get loaded from their internal list */ - if (mod->internal) { -+#if 0 -+ /* -+ * Original NSS code that uses a softoken library -+ * linked in statically. Deactivated. -+ */ - /* internal, statically get the C_GetFunctionList function */ - if (mod->isFIPS) { - entry = (CK_C_GetFunctionList) FC_GetFunctionList; -@@ -251,6 +442,35 @@ SECMOD_LoadPKCS11Module(SECMODModule *mo - mod->loaded = PR_TRUE; - return SECSuccess; - } -+#else -+ /* -+ * Workaround code that loads softoken as a dynamic library, -+ * even though the rest of NSS assumes this as the "internal" module. -+ */ -+ if (!softokenLib && PR_SUCCESS != softoken_RunLoaderOnce()) -+ return SECFailure; -+ -+ if (mod->isFIPS) { -+ entry = (CK_C_GetFunctionList) -+ PR_FindSymbol(softokenLib, "FC_GetFunctionList"); -+ } else { -+ entry = (CK_C_GetFunctionList) -+ PR_FindSymbol(softokenLib, "NSC_GetFunctionList"); -+ } -+ -+ if (!entry) -+ return SECFailure; -+ -+ if (mod->isModuleDB) { -+ mod->moduleDBFunc = (CK_C_GetFunctionList) -+ PR_FindSymbol(softokenLib, "NSC_ModuleDBFunc"); -+ } -+ -+ if (mod->moduleDBOnly) { -+ mod->loaded = PR_TRUE; -+ return SECSuccess; -+ } -+#endif - } else { - /* Not internal, load the DLL and look up C_GetFunctionList */ - if (mod->dllName == NULL) { diff --git a/nss-disable-build-freebl-softoken.patch b/nss-disable-build-freebl-softoken.patch deleted file mode 100644 index 6dc4896..0000000 --- a/nss-disable-build-freebl-softoken.patch +++ /dev/null @@ -1,386 +0,0 @@ ---- mozilla/security/nss/lib/softoken/manifest.mn.nofbst 2006-10-03 00:58:51.000000000 +0200 -+++ mozilla/security/nss/lib/softoken/manifest.mn 2007-06-16 11:16:42.000000000 +0200 -@@ -40,8 +40,8 @@ - - REQUIRES = dbm - --LIBRARY_NAME = softokn --LIBRARY_VERSION = 3 -+#LIBRARY_NAME = softokn -+#LIBRARY_VERSION = 3 - MAPFILE = $(OBJDIR)/softokn.def - - DEFINES += -DSHLIB_SUFFIX=\"$(DLL_SUFFIX)\" -DSHLIB_PREFIX=\"$(DLL_PREFIX)\" -DSOFTOKEN_LIB_NAME=\"$(notdir $(SHARED_LIBRARY))\" -@@ -66,28 +66,6 @@ - softoknt.h \ - $(NULL) - --CSRCS = \ -- dbinit.c \ -- dbmshim.c \ -- ecdecode.c \ -- fipsaudt.c \ -- fipstest.c \ -- fipstokn.c \ -- keydb.c \ -- lowcert.c \ -- lowkey.c \ -- lowpbe.c \ -- padbuf.c \ -- pcertdb.c \ -- pk11db.c \ -- pkcs11.c \ -- pkcs11c.c \ -- pkcs11u.c \ -- rsawrapr.c \ -- softkver.c \ -- tlsprf.c \ -- $(NULL) -- - ifdef NSS_ENABLE_ECC - DEFINES += -DNSS_ENABLE_ECC - endif ---- mozilla/security/nss/lib/softoken/Makefile.nofbst 2004-04-25 17:03:16.000000000 +0200 -+++ mozilla/security/nss/lib/softoken/Makefile 2007-06-16 11:16:42.000000000 +0200 -@@ -78,18 +78,3 @@ - - export:: private_export - --# On AIX 4.3, IBM xlC_r compiler (version 3.6.6) cannot compile --# pkcs11c.c in 64-bit mode for unknown reasons. A workaround is --# to compile it with optimizations turned on. (Bugzilla bug #63815) --ifeq ($(OS_TARGET)$(OS_RELEASE),AIX4.3) --ifeq ($(USE_64),1) --ifndef BUILD_OPT --$(OBJDIR)/pkcs11.o: pkcs11.c -- @$(MAKE_OBJDIR) -- $(CC) -o $@ -c -O2 $(CFLAGS) $< --$(OBJDIR)/pkcs11c.o: pkcs11c.c -- @$(MAKE_OBJDIR) -- $(CC) -o $@ -c -O2 $(CFLAGS) $< --endif --endif --endif ---- mozilla/security/nss/lib/freebl/manifest.mn.nofbst 2006-10-13 19:02:58.000000000 +0200 -+++ mozilla/security/nss/lib/freebl/manifest.mn 2007-06-16 11:16:42.000000000 +0200 -@@ -44,8 +44,10 @@ - - MODULE = nss - -+ifndef FREEBL_CHILD_BUILD - LIBRARY_NAME = freebl - LIBRARY_VERSION = 3 -+endif - - ifdef FREEBL_CHILD_BUILD - ifdef USE_ABI32_INT32 -@@ -98,56 +100,9 @@ - $(NULL) - - MPI_HDRS = mpi-config.h mpi.h mpi-priv.h mplogic.h mpprime.h logtab.h mp_gf2m.h --MPI_SRCS = mpprime.c mpmontg.c mplogic.c mpi.c mp_gf2m.c - - - ECL_HDRS = ecl-exp.h ecl.h ec2.h ecp.h ecl-priv.h --ifdef NSS_ENABLE_ECC --ECL_SRCS = ecl.c ecl_curve.c ecl_mult.c ecl_gf.c \ -- ecp_aff.c ecp_jac.c ecp_mont.c \ -- ec_naf.c ecp_jm.c --ifdef NSS_ECC_MORE_THAN_SUITE_B --ECL_SRCS += ec2_aff.c ec2_mont.c ec2_proj.c \ -- ec2_163.c ec2_193.c ec2_233.c \ -- ecp_192.c ecp_224.c ecp_256.c ecp_384.c ecp_521.c --endif --else --ECL_SRCS = $(NULL) --endif --SHA_SRCS = sha_fast.c --MPCPU_SRCS = mpcpucache.c -- --CSRCS = \ -- freeblver.c \ -- ldvector.c \ -- prng_fips1861.c \ -- sysrand.c \ -- $(SHA_SRCS) \ -- md2.c \ -- md5.c \ -- sha512.c \ -- alghmac.c \ -- rawhash.c \ -- alg2268.c \ -- arcfour.c \ -- arcfive.c \ -- desblapi.c \ -- des.c \ -- rijndael.c \ -- aeskeywrap.c \ -- dh.c \ -- ec.c \ -- pqg.c \ -- dsa.c \ -- rsa.c \ -- shvfy.c \ -- tlsprfalg.c \ -- $(MPI_SRCS) \ -- $(MPCPU_SRCS) \ -- $(ECL_SRCS) \ -- $(NULL) -- --ALL_CSRCS := $(CSRCS) - - ALL_HDRS = \ - alghmac.h \ ---- mozilla/security/nss/lib/freebl/Makefile.nofbst 2006-12-07 02:59:41.000000000 +0100 -+++ mozilla/security/nss/lib/freebl/Makefile 2007-06-16 11:16:42.000000000 +0200 -@@ -84,21 +84,17 @@ - - ifeq ($(OS_TARGET),OSF1) - DEFINES += -DMP_ASSEMBLY_MULTIPLY -DMP_NO_MP_WORD -- MPI_SRCS += mpvalpha.c - endif - - ifeq (,$(filter-out WINNT WIN95,$(OS_TARGET))) #omits WIN16 and WINCE - ifdef NS_USE_GCC - # Ideally, we want to use assembler --# ASFILES = mpi_x86.s - # DEFINES += -DMP_ASSEMBLY_MULTIPLY -DMP_ASSEMBLY_SQUARE \ - # -DMP_ASSEMBLY_DIV_2DX1D - # but we haven't figured out how to make it work, so we are not - # using assembler right now. -- ASFILES = - DEFINES += -DMP_NO_MP_WORD -DMP_USE_UINT_DIGIT - else -- MPI_SRCS += mpi_x86_asm.c - DEFINES += -DMP_ASSEMBLY_MULTIPLY -DMP_ASSEMBLY_SQUARE - DEFINES += -DMP_ASSEMBLY_DIV_2DX1D -DMP_USE_UINT_DIGIT -DMP_NO_MP_WORD - ifdef BUILD_OPT -@@ -114,7 +110,6 @@ - - ifeq ($(OS_TARGET),IRIX) - ifeq ($(USE_N32),1) -- ASFILES = mpi_mips.s - ifeq ($(NS_USE_GCC),1) - ASFLAGS = -Wp,-P -Wp,-traditional -O -mips3 - else -@@ -127,16 +122,13 @@ - - ifeq ($(OS_TARGET),Linux) - ifeq ($(CPU_ARCH),x86_64) -- ASFILES = arcfour-amd64-gas.s mpi_amd64_gas.s - ASFLAGS += -march=opteron -m64 -fPIC - DEFINES += -DNSS_BEVAND_ARCFOUR -DMPI_AMD64 -DMP_ASSEMBLY_MULTIPLY - DEFINES += -DNSS_USE_COMBA - DEFINES += -DMP_CHAR_STORE_SLOW -DMP_IS_LITTLE_ENDIAN - # DEFINES += -DMPI_AMD64_ADD -- MPI_SRCS += mpi_amd64.c mp_comba.c - endif - ifeq ($(CPU_ARCH),x86) -- ASFILES = mpi_x86.s - DEFINES += -DMP_ASSEMBLY_MULTIPLY -DMP_ASSEMBLY_SQUARE - DEFINES += -DMP_ASSEMBLY_DIV_2DX1D - DEFINES += -DMP_CHAR_STORE_SLOW -DMP_IS_LITTLE_ENDIAN -@@ -155,33 +147,11 @@ - ifeq ($(OS_TARGET), HP-UX) - ifneq ($(OS_TEST), ia64) - # PA-RISC --ASFILES += ret_cr16.s - ifndef USE_64 - FREEBL_BUILD_SINGLE_SHLIB = - HAVE_ABI32_INT32 = 1 - HAVE_ABI32_FPU = 1 - endif --ifdef FREEBL_CHILD_BUILD --ifdef USE_ABI32_INT32 --# build for DA1.1 (HP PA 1.1) 32-bit ABI build with 32-bit arithmetic -- DEFINES += -DMP_USE_UINT_DIGIT -DMP_NO_MP_WORD -- DEFINES += -DSHA_NO_LONG_LONG # avoid 64-bit arithmetic in SHA512 --else --ifdef USE_64 --# this builds for DA2.0W (HP PA 2.0 Wide), the LP64 ABI, using 64-bit digits -- MPI_SRCS += mpi_hp.c -- ASFILES += hpma512.s hppa20.s -- DEFINES += -DMP_ASSEMBLY_MULTIPLY -DMP_ASSEMBLY_SQUARE --else --# this builds for DA2.0 (HP PA 2.0 Narrow) ABI32_FPU model --# (the 32-bit ABI with 64-bit registers) using 64-bit digits -- MPI_SRCS += mpi_hp.c -- ASFILES += hpma512.s hppa20.s -- DEFINES += -DMP_ASSEMBLY_MULTIPLY -DMP_ASSEMBLY_SQUARE -- ARCHFLAG = -Aa +e +DA2.0 +DS2.0 --endif --endif --endif - endif - endif - -@@ -326,7 +296,6 @@ - ifdef USE_ABI32_INT32 - # this builds for Sparc v8 pure 32-bit architecture - DEFINES += -DMP_USE_UINT_DIGIT -DMP_ASSEMBLY_MULTIPLY -- ASFILES = mpv_sparcv8x.s - DEFINES += -DSHA_NO_LONG_LONG # avoid 64-bit arithmetic in SHA512 - endif - ifdef USE_ABI32_INT64 -@@ -337,8 +306,6 @@ - ifdef USE_ABI32_FPU - # this builds for Sparc v8+a ABI32_FPU architecture, 64-bit registers, - # 32-bit ABI, it uses FPU code, and 32-bit word size -- MPI_SRCS += mpi_sparc.c -- ASFILES = mpv_sparcv8.s montmulfv8.s - DEFINES += -DMP_NO_MP_WORD -DMP_USE_UINT_DIGIT -DMP_ASSEMBLY_MULTIPLY - DEFINES += -DMP_USING_MONT_MULF -DMP_MONT_USE_MP_MUL - ECL_USE_FP = 1 -@@ -350,8 +317,6 @@ - ifdef USE_ABI64_FPU - # this builds for Sparc v9a pure 64-bit architecture - # It uses floating point, and 32-bit word size -- MPI_SRCS += mpi_sparc.c -- ASFILES = mpv_sparcv9.s montmulfv9.s - DEFINES += -DMP_NO_MP_WORD -DMP_USE_UINT_DIGIT -DMP_ASSEMBLY_MULTIPLY - DEFINES += -DMP_USING_MONT_MULF -DMP_MONT_USE_MP_MUL - ECL_USE_FP = 1 -@@ -367,29 +332,22 @@ - ifeq ($(USE_64),1) - # Solaris for AMD64 - ifdef NS_USE_GCC -- ASFILES = arcfour-amd64-gas.s mpi_amd64_gas.s - ASFLAGS += -march=opteron -m64 -fPIC -- MPI_SRCS += mp_comba.c - else -- ASFILES = arcfour-amd64-sun.s mpi_amd64_sun.s sha-fast-amd64-sun.s -- ASFILES += mp_comba_amd64_sun.s mpcpucache_amd64.s - ASFLAGS += -xarch=generic64 -K PIC - SHA_SRCS = - MPCPU_SRCS = - endif - DEFINES += -DNSS_BEVAND_ARCFOUR -DMPI_AMD64 -DMP_ASSEMBLY_MULTIPLY - DEFINES += -DNSS_USE_COMBA -- MPI_SRCS += mpi_amd64.c - else - # Solaris x86 - DEFINES += -D_X86_ - DEFINES += -DMP_USE_UINT_DIGIT - DEFINES += -DMP_ASSEMBLY_MULTIPLY -DMP_ASSEMBLY_SQUARE - DEFINES += -DMP_ASSEMBLY_DIV_2DX1D -- ASFILES = mpi_i86pc.s - ifndef NS_USE_GCC - MPCPU_SRCS = -- ASFILES += mpcpucache_x86.s - endif - endif - endif # Solaris for non-sparc family CPUs -@@ -399,7 +357,6 @@ - ifdef ECL_USE_FP - #enable floating point ECC code - DEFINES += -DECL_USE_FP -- ECL_SRCS += ecp_fp160.c ecp_fp192.c ecp_fp224.c ecp_fp.c - ECL_HDRS += ecp_fp.h - endif - endif # NSS_ENABLE_ECC -@@ -436,26 +393,12 @@ - - DEFINES += -DMP_API_COMPATIBLE - --MPI_USERS = dh.c pqg.c dsa.c rsa.c ec.c -- --MPI_OBJS = $(addprefix $(OBJDIR)/$(PROG_PREFIX), $(MPI_SRCS:.c=$(OBJ_SUFFIX))) --MPI_OBJS += $(addprefix $(OBJDIR)/$(PROG_PREFIX), $(MPI_USERS:.c=$(OBJ_SUFFIX))) -- - $(MPI_OBJS): $(MPI_HDRS) - --ECL_USERS = ec.c -- --ECL_OBJS = $(addprefix $(OBJDIR)/$(PROG_PREFIX), $(ECL_SRCS:.c=$(OBJ_SUFFIX)) $(ECL_ASM_SRCS:$(ASM_SUFFIX)=$(OBJ_SUFFIX))) --ECL_OBJS += $(addprefix $(OBJDIR)/$(PROG_PREFIX), $(ECL_USERS:.c=$(OBJ_SUFFIX))) -- - $(ECL_OBJS): $(ECL_HDRS) - - - --$(OBJDIR)/sysrand$(OBJ_SUFFIX): sysrand.c unix_rand.c win_rand.c mac_rand.c os2_rand.c -- --$(OBJDIR)/$(PROG_PREFIX)mpprime$(OBJ_SUFFIX): primes.c -- - $(OBJDIR)/ldvector$(OBJ_SUFFIX) $(OBJDIR)/loader$(OBJ_SUFFIX) : loader.h - - ifeq ($(SYSV_SPARC),1) -@@ -468,8 +411,6 @@ - @$(MAKE_OBJDIR) - $(SOLARIS_AS) -o $@ $(SOLARIS_AS_FLAGS) $< - --$(OBJDIR)/mpmontg.o: mpmontg.c montmulf.h -- - endif - - ifndef FREEBL_CHILD_BUILD -@@ -565,25 +506,3 @@ - - endif # FREEBL_CHILD_BUILD - -- --# Bugzilla Bug 209827: disable optimization to work around what appears --# to be a VACPP optimizer bug. --ifdef XP_OS2_VACPP --$(OBJDIR)/alg2268.obj: alg2268.c -- @$(MAKE_OBJDIR) -- $(CC) -Fo$@ -c $(filter-out /O+, $(CFLAGS)) $(call core_abspath,$<) --endif -- --# Bugzilla Bug 333917: the non-x86 code in desblapi.c seems to violate --# ANSI C's strict aliasing rules. --ifeq ($(OS_TARGET),Linux) --ifneq ($(CPU_ARCH),x86) --$(OBJDIR)/$(PROG_PREFIX)desblapi$(OBJ_SUFFIX): desblapi.c -- @$(MAKE_OBJDIR) --ifdef NEED_ABSOLUTE_PATH -- $(CC) -o $@ -c $(CFLAGS) -fno-strict-aliasing $(call core_abspath,$<) --else -- $(CC) -o $@ -c $(CFLAGS) -fno-strict-aliasing $< --endif --endif --endif ---- mozilla/security/nss/cmd/shlibsign/Makefile.nofbst 2006-12-07 02:59:40.000000000 +0100 -+++ mozilla/security/nss/cmd/shlibsign/Makefile 2007-06-16 11:16:42.000000000 +0200 -@@ -60,9 +60,9 @@ - - # sign any and all shared libraries that contain the word freebl - --CHECKLIBS = $(DIST)/lib/$(DLL_PREFIX)softokn3.$(DLL_SUFFIX) --CHECKLIBS += $(wildcard $(DIST)/lib/$(DLL_PREFIX)freebl*3.$(DLL_SUFFIX)) --CHECKLOC = $(CHECKLIBS:.$(DLL_SUFFIX)=.chk) -+#CHECKLIBS = $(DIST)/lib/$(DLL_PREFIX)softokn3.$(DLL_SUFFIX) -+#CHECKLIBS += $(wildcard $(DIST)/lib/$(DLL_PREFIX)freebl*3.$(DLL_SUFFIX)) -+#CHECKLOC = $(CHECKLIBS:.$(DLL_SUFFIX)=.chk) - - MD_LIB_RELEASE_FILES = $(CHECKLOC) - ALL_TRASH += $(CHECKLOC) ---- mozilla/security/nss/cmd/platlibs.mk.nofbst 2006-11-17 03:13:16.000000000 +0100 -+++ mozilla/security/nss/cmd/platlibs.mk 2007-06-16 11:16:42.000000000 +0200 -@@ -101,7 +101,6 @@ - $(DIST)/lib/$(LIB_PREFIX)cryptohi.$(LIB_SUFFIX) \ - $(DIST)/lib/$(LIB_PREFIX)pk11wrap.$(LIB_SUFFIX) \ - $(DIST)/lib/$(LIB_PREFIX)certdb.$(LIB_SUFFIX) \ -- $(DIST)/lib/$(LIB_PREFIX)softokn.$(LIB_SUFFIX) \ - $(CRYPTOLIB) \ - $(DIST)/lib/$(LIB_PREFIX)secutil.$(LIB_SUFFIX) \ - $(DIST)/lib/$(LIB_PREFIX)nsspki.$(LIB_SUFFIX) \ -@@ -143,7 +142,6 @@ - $(DIST)/lib/$(LIB_PREFIX)certhi.$(LIB_SUFFIX) \ - $(DIST)/lib/$(LIB_PREFIX)nsspki.$(LIB_SUFFIX) \ - $(DIST)/lib/$(LIB_PREFIX)pk11wrap.$(LIB_SUFFIX) \ -- $(DIST)/lib/$(LIB_PREFIX)softokn.$(LIB_SUFFIX) \ - $(DIST)/lib/$(LIB_PREFIX)certdb.$(LIB_SUFFIX) \ - $(DIST)/lib/$(LIB_PREFIX)nsspki.$(LIB_SUFFIX) \ - $(DIST)/lib/$(LIB_PREFIX)nssdev.$(LIB_SUFFIX) \ -@@ -225,10 +223,6 @@ - endif - endif - --ifeq ($(OS_ARCH), Darwin) --EXTRA_SHARED_LIBS += -dylib_file @executable_path/libsoftokn3.dylib:$(DIST)/lib/libsoftokn3.dylib --endif -- - - # $(PROGRAM) has NO explicit dependencies on $(EXTRA_SHARED_LIBS) - # $(EXTRA_SHARED_LIBS) come before $(OS_LIBS), except on AIX. diff --git a/nss-limit-suite-b.patch b/nss-limit-suite-b.patch deleted file mode 100644 index 410088e..0000000 --- a/nss-limit-suite-b.patch +++ /dev/null @@ -1,916 +0,0 @@ -Index: mozilla/security/coreconf/config.mk -diff -u mozilla/security/coreconf/config.mk:1.17.28.1 mozilla/security/coreconf/config.mk:1.17.28.2 ---- mozilla/security/coreconf/config.mk:1.17.28.1 Sat Jan 21 19:01:27 2006 -+++ mozilla/security/coreconf/config.mk Fri Apr 28 03:36:22 2006 -@@ -177,3 +177,7 @@ - ifdef NSS_ENABLE_ECC - DEFINES += -DNSS_ENABLE_ECC - endif -+ -+ifdef NSS_ECC_MORE_THAN_SUITE_B -+DEFINES += -DNSS_ECC_MORE_THAN_SUITE_B -+endif -Index: mozilla/security/nss/cmd/selfserv/selfserv.c -diff -u mozilla/security/nss/cmd/selfserv/selfserv.c:1.68.2.5 mozilla/security/nss/cmd/selfserv/selfserv.c:1.68.2.6 ---- mozilla/security/nss/cmd/selfserv/selfserv.c:1.68.2.5 Sat Apr 22 05:19:47 2006 -+++ mozilla/security/nss/cmd/selfserv/selfserv.c Fri Apr 28 03:35:33 2006 -@@ -1806,7 +1806,11 @@ - exit(0); - } - -- if ((nickName == NULL) && (fNickName == NULL)) { -+ if ((nickName == NULL) && (fNickName == NULL) -+#ifdef NSS_ENABLE_ECC -+ && (ecNickName == NULL) -+#endif -+ ) { - fprintf(stderr, "Required arg '-n' (rsa nickname) not supplied.\n"); - fprintf(stderr, "Run '%s -h' for usage information.\n", progName); - exit(6); -Index: mozilla/security/nss/cmd/bltest/blapitest.c -diff -u mozilla/security/nss/cmd/bltest/blapitest.c:1.46.2.1 mozilla/security/nss/cmd/bltest/blapitest.c:1.46.2.2 ---- mozilla/security/nss/cmd/bltest/blapitest.c:1.46.2.1 Wed Feb 22 22:18:50 2006 -+++ mozilla/security/nss/cmd/bltest/blapitest.c Fri Apr 28 03:35:32 2006 -@@ -2499,9 +2499,12 @@ - case bltestECDSA: - if (td) - fprintf(stdout, "%12s", "ec_curve"); -- else -+ else { -+ ECCurveName curveName = info->params.ecdsa.eckey->ecParams.name; - fprintf(stdout, "%12s", -- ecCurve_map[info->params.ecdsa.eckey->ecParams.name]->text); -+ ecCurve_map[curveName]? ecCurve_map[curveName]->text: -+ "Unsupported curve"); -+ } - break; - #endif - case bltestMD2: -Index: mozilla/security/nss/lib/ssl/sslimpl.h -diff -u mozilla/security/nss/lib/ssl/sslimpl.h:1.42.2.6 mozilla/security/nss/lib/ssl/sslimpl.h:1.42.2.7 ---- mozilla/security/nss/lib/ssl/sslimpl.h:1.42.2.6 Sun Apr 23 03:05:42 2006 -+++ mozilla/security/nss/lib/ssl/sslimpl.h Fri Apr 28 03:35:32 2006 -@@ -39,7 +39,7 @@ - * the terms of any one of the MPL, the GPL or the LGPL. - * - * ***** END LICENSE BLOCK ***** */ --/* $Id: sslimpl.h,v 1.42.2.6 2006/04/23 03:05:42 nelson%bolyard.com Exp $ */ -+/* $Id: sslimpl.h,v 1.42.2.7 2006/04/28 03:35:32 rrelyea%redhat.com Exp $ */ - - #ifndef __sslimpl_h_ - #define __sslimpl_h_ -@@ -180,7 +180,7 @@ - #define NUM_MIXERS 9 - - /* Mask of the 25 named curves we support. */ --#ifdef NSS_ECC_ONLY_SUITE_B -+#ifndef NSS_ECC_MORE_THAN_SUITE_B - #define SSL3_SUPPORTED_CURVES_MASK 0x3800000 /* only 3 curves, suite B*/ - #else - #define SSL3_SUPPORTED_CURVES_MASK 0x3fffffe -Index: mozilla/security/nss/lib/ssl/ssl3ecc.c -diff -u mozilla/security/nss/lib/ssl/ssl3ecc.c:1.3.2.5 mozilla/security/nss/lib/ssl/ssl3ecc.c:1.3.2.6 ---- mozilla/security/nss/lib/ssl/ssl3ecc.c:1.3.2.5 Sun Apr 23 03:05:42 2006 -+++ mozilla/security/nss/lib/ssl/ssl3ecc.c Fri Apr 28 03:35:32 2006 -@@ -40,7 +40,7 @@ - * ***** END LICENSE BLOCK ***** */ - - /* ECC code moved here from ssl3con.c */ --/* $Id: ssl3ecc.c,v 1.3.2.5 2006/04/23 03:05:42 nelson%bolyard.com Exp $ */ -+/* $Id: ssl3ecc.c,v 1.3.2.6 2006/04/28 03:35:32 rrelyea%redhat.com Exp $ */ - - #include "nssrenam.h" - #include "nss.h" -@@ -1030,9 +1030,9 @@ - - #define BE(n) 0, n - --#ifdef NSS_ECC_ONLY_SUITE_B -+#ifndef NSS_ECC_MORE_THAN_SUITE_B - /* Prefabricated TLS client hello extension, Elliptic Curves List, -- * offers only 3 curves, the Suite B curves, 23-35 -+ * offers only 3 curves, the Suite B curves, 23-25 - */ - static const PRUint8 EClist[12] = { - BE(10), /* Extension type */ -Index: mozilla/security/nss/lib/smime/cmssiginfo.c -diff -u mozilla/security/nss/lib/smime/cmssiginfo.c:1.29 mozilla/security/nss/lib/smime/cmssiginfo.c:1.29.2.1 ---- mozilla/security/nss/lib/smime/cmssiginfo.c:1.29 Fri Sep 2 01:24:56 2005 -+++ mozilla/security/nss/lib/smime/cmssiginfo.c Fri Apr 28 03:35:31 2006 -@@ -38,7 +38,7 @@ - /* - * CMS signerInfo methods. - * -- * $Id: cmssiginfo.c,v 1.29 2005/09/02 01:24:56 wtchang%redhat.com Exp $ -+ * $Id: cmssiginfo.c,v 1.29.2.1 2006/04/28 03:35:31 rrelyea%redhat.com Exp $ - */ - - #include "cmslocal.h" -@@ -386,7 +386,9 @@ - case SEC_OID_ANSIX9_DSA_SIGNATURE_WITH_SHA1_DIGEST: - case SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION: - case SEC_OID_PKCS1_MD5_WITH_RSA_ENCRYPTION: -+#ifdef NSS_ECC_MORE_THAN_SUITE_B - case SEC_OID_ANSIX962_EC_PUBLIC_KEY: -+#endif - /* ok */ - break; - case SEC_OID_UNKNOWN: -Index: mozilla/security/nss/lib/pkcs7/p7decode.c -diff -u mozilla/security/nss/lib/pkcs7/p7decode.c:1.20 mozilla/security/nss/lib/pkcs7/p7decode.c:1.20.2.1 ---- mozilla/security/nss/lib/pkcs7/p7decode.c:1.20 Mon Oct 3 22:01:56 2005 -+++ mozilla/security/nss/lib/pkcs7/p7decode.c Fri Apr 28 03:35:30 2006 -@@ -38,7 +38,7 @@ - /* - * PKCS7 decoding, verification. - * -- * $Id: p7decode.c,v 1.20 2005/10/03 22:01:56 relyea%netscape.com Exp $ -+ * $Id: p7decode.c,v 1.20.2.1 2006/04/28 03:35:30 rrelyea%redhat.com Exp $ - */ - - #include "nssrenam.h" -@@ -1665,7 +1665,9 @@ - algiddata = SECOID_FindOID (&(signerinfo->digestEncAlg.algorithm)); - if (algiddata == NULL || - ((algiddata->offset != SEC_OID_PKCS1_RSA_ENCRYPTION) && -+#ifdef NSS_ECC_MORE_THAN_SUITE_B - (algiddata->offset != SEC_OID_ANSIX962_EC_PUBLIC_KEY) && -+#endif - (algiddata->offset != SEC_OID_ANSIX9_DSA_SIGNATURE))) { - PORT_SetError (SEC_ERROR_PKCS7_BAD_SIGNATURE); - goto done; -Index: mozilla/security/nss/lib/freebl/ecl/ecl_curve.c -diff -u mozilla/security/nss/lib/freebl/ecl/ecl_curve.c:1.2 mozilla/security/nss/lib/freebl/ecl/ecl_curve.c:1.2.28.1 ---- mozilla/security/nss/lib/freebl/ecl/ecl_curve.c:1.2 Sun Apr 25 15:03:09 2004 -+++ mozilla/security/nss/lib/freebl/ecl/ecl_curve.c Fri Apr 28 03:35:30 2006 -@@ -91,7 +91,8 @@ - ECCurveParams * - EC_GetNamedCurveParams(const ECCurveName name) - { -- if ((name <= ECCurve_noName) || (ECCurve_pastLastCurve <= name)) { -+ if ((name <= ECCurve_noName) || (ECCurve_pastLastCurve <= name) || -+ (ecCurve_map[name] == NULL)) { - return NULL; - } else { - return ECCurveParams_dup(ecCurve_map[name]); -Index: mozilla/security/nss/lib/freebl/ecl/ecl.c -diff -u mozilla/security/nss/lib/freebl/ecl/ecl.c:1.5.2.2 mozilla/security/nss/lib/freebl/ecl/ecl.c:1.5.2.3 ---- mozilla/security/nss/lib/freebl/ecl/ecl.c:1.5.2.2 Fri Mar 31 00:26:49 2006 -+++ mozilla/security/nss/lib/freebl/ecl/ecl.c Fri Apr 28 03:35:30 2006 -@@ -164,6 +164,7 @@ - return group; - } - -+#ifdef NSS_ECC_MORE_THAN_SUITE_B - /* Construct a generic ECGroup for elliptic curves over binary polynomial - * fields. */ - ECGroup * -@@ -205,6 +206,7 @@ - } - return group; - } -+#endif - - /* Construct ECGroup from hex parameters and name, if any. Called by - * ECGroup_fromHex and ECGroup_fromName. */ -@@ -246,6 +248,7 @@ - - /* determine which optimizations (if any) to use */ - if (params->field == ECField_GFp) { -+#ifdef NSS_ECC_MORE_THAN_SUITE_B - switch (name) { - #ifdef ECL_USE_FP - case ECCurve_SECG_PRIME_160R1: -@@ -302,10 +305,12 @@ - break; - default: - /* use generic arithmetic */ -+#endif - group = - ECGroup_consGFp_mont(&irr, &curvea, &curveb, &genx, &geny, - &order, params->cofactor); - if (group == NULL) { res = MP_UNDEF; goto CLEANUP; } -+#ifdef NSS_ECC_MORE_THAN_SUITE_B - } - } else if (params->field == ECField_GF2m) { - group = ECGroup_consGF2m(&irr, NULL, &curvea, &curveb, &genx, &geny, &order, params->cofactor); -@@ -321,6 +326,7 @@ - (name == ECCurve_NIST_B233)) { - MP_CHECKOK(ec_group_set_gf2m233(group, name)); - } -+#endif - } - - /* set name, if any */ -Index: mozilla/security/nss/lib/freebl/ecl/ecl-curve.h -diff -u mozilla/security/nss/lib/freebl/ecl/ecl-curve.h:1.2.28.2 mozilla/security/nss/lib/freebl/ecl/ecl-curve.h:1.2.28.3 ---- mozilla/security/nss/lib/freebl/ecl/ecl-curve.h:1.2.28.2 Mon Feb 27 23:26:00 2006 -+++ mozilla/security/nss/lib/freebl/ecl/ecl-curve.h Fri Apr 28 03:35:30 2006 -@@ -42,25 +42,6 @@ - #ifndef __ecl_curve_h_ - #define __ecl_curve_h_ - --/* NIST prime curves */ --static const ECCurveParams ecCurve_NIST_P192 = { -- "NIST-P192", ECField_GFp, 192, -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF", -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC", -- "64210519E59C80E70FA7E9AB72243049FEB8DEECC146B9B1", -- "188DA80EB03090F67CBF20EB43A18800F4FF0AFD82FF1012", -- "07192B95FFC8DA78631011ED6B24CDD573F977A11E794811", -- "FFFFFFFFFFFFFFFFFFFFFFFF99DEF836146BC9B1B4D22831", 1 --}; --static const ECCurveParams ecCurve_NIST_P224 = { -- "NIST-P224", ECField_GFp, 224, -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000000000000001", -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFFFFFFFFFE", -- "B4050A850C04B3ABF54132565044B0B7D7BFD8BA270B39432355FFB4", -- "B70E0CBD6BB4BF7F321390B94A03C1D356C21122343280D6115C1D21", -- "BD376388B5F723FB4C22DFE6CD4375A05A07476444D5819985007E34", -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFF16A2E0B8F03E13DD29455C5C2A3D", 1 --}; - static const ECCurveParams ecCurve_NIST_P256 = { - "NIST-P256", ECField_GFp, 256, - "FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFF", -@@ -70,6 +51,7 @@ - "4FE342E2FE1A7F9B8EE7EB4A7C0F9E162BCE33576B315ECECBB6406837BF51F5", - "FFFFFFFF00000000FFFFFFFFFFFFFFFFBCE6FAADA7179E84F3B9CAC2FC632551", 1 - }; -+ - static const ECCurveParams ecCurve_NIST_P384 = { - "NIST-P384", ECField_GFp, 384, - "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFF", -@@ -80,6 +62,7 @@ - "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC7634D81F4372DDF581A0DB248B0A77AECEC196ACCC52973", - 1 - }; -+ - static const ECCurveParams ecCurve_NIST_P521 = { - "NIST-P521", ECField_GFp, 521, - "01FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF", -@@ -91,558 +74,67 @@ - 1 - }; - --/* NIST binary curves */ --static const ECCurveParams ecCurve_NIST_K163 = { -- "NIST-K163", ECField_GF2m, 163, -- "0800000000000000000000000000000000000000C9", -- "000000000000000000000000000000000000000001", -- "000000000000000000000000000000000000000001", -- "02FE13C0537BBC11ACAA07D793DE4E6D5E5C94EEE8", -- "0289070FB05D38FF58321F2E800536D538CCDAA3D9", -- "04000000000000000000020108A2E0CC0D99F8A5EF", 2 --}; --static const ECCurveParams ecCurve_NIST_B163 = { -- "NIST-B163", ECField_GF2m, 163, -- "0800000000000000000000000000000000000000C9", -- "000000000000000000000000000000000000000001", -- "020A601907B8C953CA1481EB10512F78744A3205FD", -- "03F0EBA16286A2D57EA0991168D4994637E8343E36", -- "00D51FBC6C71A0094FA2CDD545B11C5C0C797324F1", -- "040000000000000000000292FE77E70C12A4234C33", 2 --}; --static const ECCurveParams ecCurve_NIST_K233 = { -- "NIST-K233", ECField_GF2m, 233, -- "020000000000000000000000000000000000000004000000000000000001", -- "000000000000000000000000000000000000000000000000000000000000", -- "000000000000000000000000000000000000000000000000000000000001", -- "017232BA853A7E731AF129F22FF4149563A419C26BF50A4C9D6EEFAD6126", -- "01DB537DECE819B7F70F555A67C427A8CD9BF18AEB9B56E0C11056FAE6A3", -- "008000000000000000000000000000069D5BB915BCD46EFB1AD5F173ABDF", 4 --}; --static const ECCurveParams ecCurve_NIST_B233 = { -- "NIST-B233", ECField_GF2m, 233, -- "020000000000000000000000000000000000000004000000000000000001", -- "000000000000000000000000000000000000000000000000000000000001", -- "0066647EDE6C332C7F8C0923BB58213B333B20E9CE4281FE115F7D8F90AD", -- "00FAC9DFCBAC8313BB2139F1BB755FEF65BC391F8B36F8F8EB7371FD558B", -- "01006A08A41903350678E58528BEBF8A0BEFF867A7CA36716F7E01F81052", -- "01000000000000000000000000000013E974E72F8A6922031D2603CFE0D7", 2 --}; --static const ECCurveParams ecCurve_NIST_K283 = { -- "NIST-K283", ECField_GF2m, 283, -- "0800000000000000000000000000000000000000000000000000000000000000000010A1", -- "000000000000000000000000000000000000000000000000000000000000000000000000", -- "000000000000000000000000000000000000000000000000000000000000000000000001", -- "0503213F78CA44883F1A3B8162F188E553CD265F23C1567A16876913B0C2AC2458492836", -- "01CCDA380F1C9E318D90F95D07E5426FE87E45C0E8184698E45962364E34116177DD2259", -- "01FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFE9AE2ED07577265DFF7F94451E061E163C61", -- 4 --}; --static const ECCurveParams ecCurve_NIST_B283 = { -- "NIST-B283", ECField_GF2m, 283, -- "0800000000000000000000000000000000000000000000000000000000000000000010A1", -- "000000000000000000000000000000000000000000000000000000000000000000000001", -- "027B680AC8B8596DA5A4AF8A19A0303FCA97FD7645309FA2A581485AF6263E313B79A2F5", -- "05F939258DB7DD90E1934F8C70B0DFEC2EED25B8557EAC9C80E2E198F8CDBECD86B12053", -- "03676854FE24141CB98FE6D4B20D02B4516FF702350EDDB0826779C813F0DF45BE8112F4", -- "03FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEF90399660FC938A90165B042A7CEFADB307", -- 2 --}; --static const ECCurveParams ecCurve_NIST_K409 = { -- "NIST-K409", ECField_GF2m, 409, -- "02000000000000000000000000000000000000000000000000000000000000000000000000000000008000000000000000000001", -- "00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000", -- "00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001", -- "0060F05F658F49C1AD3AB1890F7184210EFD0987E307C84C27ACCFB8F9F67CC2C460189EB5AAAA62EE222EB1B35540CFE9023746", -- "01E369050B7C4E42ACBA1DACBF04299C3460782F918EA427E6325165E9EA10E3DA5F6C42E9C55215AA9CA27A5863EC48D8E0286B", -- "007FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFE5F83B2D4EA20400EC4557D5ED3E3E7CA5B4B5C83B8E01E5FCF", -- 4 --}; --static const ECCurveParams ecCurve_NIST_B409 = { -- "NIST-B409", ECField_GF2m, 409, -- "02000000000000000000000000000000000000000000000000000000000000000000000000000000008000000000000000000001", -- "00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001", -- "0021A5C2C8EE9FEB5C4B9A753B7B476B7FD6422EF1F3DD674761FA99D6AC27C8A9A197B272822F6CD57A55AA4F50AE317B13545F", -- "015D4860D088DDB3496B0C6064756260441CDE4AF1771D4DB01FFE5B34E59703DC255A868A1180515603AEAB60794E54BB7996A7", -- "0061B1CFAB6BE5F32BBFA78324ED106A7636B9C5A7BD198D0158AA4F5488D08F38514F1FDF4B4F40D2181B3681C364BA0273C706", -- "010000000000000000000000000000000000000000000000000001E2AAD6A612F33307BE5FA47C3C9E052F838164CD37D9A21173", -- 2 --}; --static const ECCurveParams ecCurve_NIST_K571 = { -- "NIST-K571", ECField_GF2m, 571, -- "080000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000425", -- "000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000", -- "000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001", -- "026EB7A859923FBC82189631F8103FE4AC9CA2970012D5D46024804801841CA44370958493B205E647DA304DB4CEB08CBBD1BA39494776FB988B47174DCA88C7E2945283A01C8972", -- "0349DC807F4FBF374F4AEADE3BCA95314DD58CEC9F307A54FFC61EFC006D8A2C9D4979C0AC44AEA74FBEBBB9F772AEDCB620B01A7BA7AF1B320430C8591984F601CD4C143EF1C7A3", -- "020000000000000000000000000000000000000000000000000000000000000000000000131850E1F19A63E4B391A8DB917F4138B630D84BE5D639381E91DEB45CFE778F637C1001", -- 4 --}; --static const ECCurveParams ecCurve_NIST_B571 = { -- "NIST-B571", ECField_GF2m, 571, -- "080000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000425", -- "000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001", -- "02F40E7E2221F295DE297117B7F3D62F5C6A97FFCB8CEFF1CD6BA8CE4A9A18AD84FFABBD8EFA59332BE7AD6756A66E294AFD185A78FF12AA520E4DE739BACA0C7FFEFF7F2955727A", -- "0303001D34B856296C16C0D40D3CD7750A93D1D2955FA80AA5F40FC8DB7B2ABDBDE53950F4C0D293CDD711A35B67FB1499AE60038614F1394ABFA3B4C850D927E1E7769C8EEC2D19", -- "037BF27342DA639B6DCCFFFEB73D69D78C6C27A6009CBBCA1980F8533921E8A684423E43BAB08A576291AF8F461BB2A8B3531D2F0485C19B16E2F1516E23DD3C1A4827AF1B8AC15B", -- "03FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFE661CE18FF55987308059B186823851EC7DD9CA1161DE93D5174D66E8382E9BB2FE84E47", -- 2 --}; -- --/* ANSI X9.62 prime curves */ --static const ECCurveParams ecCurve_X9_62_PRIME_192V2 = { -- "X9.62 P-192V2", ECField_GFp, 192, -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF", -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC", -- "CC22D6DFB95C6B25E49C0D6364A4E5980C393AA21668D953", -- "EEA2BAE7E1497842F2DE7769CFE9C989C072AD696F48034A", -- "6574D11D69B6EC7A672BB82A083DF2F2B0847DE970B2DE15", -- "FFFFFFFFFFFFFFFFFFFFFFFE5FB1A724DC80418648D8DD31", 1 --}; --static const ECCurveParams ecCurve_X9_62_PRIME_192V3 = { -- "X9.62 P-192V3", ECField_GFp, 192, -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF", -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC", -- "22123DC2395A05CAA7423DAECCC94760A7D462256BD56916", -- "7D29778100C65A1DA1783716588DCE2B8B4AEE8E228F1896", -- "38A90F22637337334B49DCB66A6DC8F9978ACA7648A943B0", -- "FFFFFFFFFFFFFFFFFFFFFFFF7A62D031C83F4294F640EC13", 1 --}; --static const ECCurveParams ecCurve_X9_62_PRIME_239V1 = { -- "X9.62 P-239V1", ECField_GFp, 239, -- "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFF", -- "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFC", -- "6B016C3BDCF18941D0D654921475CA71A9DB2FB27D1D37796185C2942C0A", -- "0FFA963CDCA8816CCC33B8642BEDF905C3D358573D3F27FBBD3B3CB9AAAF", -- "7DEBE8E4E90A5DAE6E4054CA530BA04654B36818CE226B39FCCB7B02F1AE", -- "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFF9E5E9A9F5D9071FBD1522688909D0B", 1 --}; --static const ECCurveParams ecCurve_X9_62_PRIME_239V2 = { -- "X9.62 P-239V2", ECField_GFp, 239, -- "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFF", -- "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFC", -- "617FAB6832576CBBFED50D99F0249C3FEE58B94BA0038C7AE84C8C832F2C", -- "38AF09D98727705120C921BB5E9E26296A3CDCF2F35757A0EAFD87B830E7", -- "5B0125E4DBEA0EC7206DA0FC01D9B081329FB555DE6EF460237DFF8BE4BA", -- "7FFFFFFFFFFFFFFFFFFFFFFF800000CFA7E8594377D414C03821BC582063", 1 --}; --static const ECCurveParams ecCurve_X9_62_PRIME_239V3 = { -- "X9.62 P-239V3", ECField_GFp, 239, -- "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFF", -- "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFC", -- "255705FA2A306654B1F4CB03D6A750A30C250102D4988717D9BA15AB6D3E", -- "6768AE8E18BB92CFCF005C949AA2C6D94853D0E660BBF854B1C9505FE95A", -- "1607E6898F390C06BC1D552BAD226F3B6FCFE48B6E818499AF18E3ED6CF3", -- "7FFFFFFFFFFFFFFFFFFFFFFF7FFFFF975DEB41B3A6057C3C432146526551", 1 --}; -- --/* ANSI X9.62 binary curves */ --static const ECCurveParams ecCurve_X9_62_CHAR2_PNB163V1 = { -- "X9.62 C2-PNB163V1", ECField_GF2m, 163, -- "080000000000000000000000000000000000000107", -- "072546B5435234A422E0789675F432C89435DE5242", -- "00C9517D06D5240D3CFF38C74B20B6CD4D6F9DD4D9", -- "07AF69989546103D79329FCC3D74880F33BBE803CB", -- "01EC23211B5966ADEA1D3F87F7EA5848AEF0B7CA9F", -- "0400000000000000000001E60FC8821CC74DAEAFC1", 2 --}; --static const ECCurveParams ecCurve_X9_62_CHAR2_PNB163V2 = { -- "X9.62 C2-PNB163V2", ECField_GF2m, 163, -- "080000000000000000000000000000000000000107", -- "0108B39E77C4B108BED981ED0E890E117C511CF072", -- "0667ACEB38AF4E488C407433FFAE4F1C811638DF20", -- "0024266E4EB5106D0A964D92C4860E2671DB9B6CC5", -- "079F684DDF6684C5CD258B3890021B2386DFD19FC5", -- "03FFFFFFFFFFFFFFFFFFFDF64DE1151ADBB78F10A7", 2 --}; --static const ECCurveParams ecCurve_X9_62_CHAR2_PNB163V3 = { -- "X9.62 C2-PNB163V3", ECField_GF2m, 163, -- "080000000000000000000000000000000000000107", -- "07A526C63D3E25A256A007699F5447E32AE456B50E", -- "03F7061798EB99E238FD6F1BF95B48FEEB4854252B", -- "02F9F87B7C574D0BDECF8A22E6524775F98CDEBDCB", -- "05B935590C155E17EA48EB3FF3718B893DF59A05D0", -- "03FFFFFFFFFFFFFFFFFFFE1AEE140F110AFF961309", 2 --}; --static const ECCurveParams ecCurve_X9_62_CHAR2_PNB176V1 = { -- "X9.62 C2-PNB176V1", ECField_GF2m, 176, -- "0100000000000000000000000000000000080000000007", -- "E4E6DB2995065C407D9D39B8D0967B96704BA8E9C90B", -- "5DDA470ABE6414DE8EC133AE28E9BBD7FCEC0AE0FFF2", -- "8D16C2866798B600F9F08BB4A8E860F3298CE04A5798", -- "6FA4539C2DADDDD6BAB5167D61B436E1D92BB16A562C", -- "00010092537397ECA4F6145799D62B0A19CE06FE26AD", 0xFF6E --}; --static const ECCurveParams ecCurve_X9_62_CHAR2_TNB191V1 = { -- "X9.62 C2-TNB191V1", ECField_GF2m, 191, -- "800000000000000000000000000000000000000000000201", -- "2866537B676752636A68F56554E12640276B649EF7526267", -- "2E45EF571F00786F67B0081B9495A3D95462F5DE0AA185EC", -- "36B3DAF8A23206F9C4F299D7B21A9C369137F2C84AE1AA0D", -- "765BE73433B3F95E332932E70EA245CA2418EA0EF98018FB", -- "40000000000000000000000004A20E90C39067C893BBB9A5", 2 --}; --static const ECCurveParams ecCurve_X9_62_CHAR2_TNB191V2 = { -- "X9.62 C2-TNB191V2", ECField_GF2m, 191, -- "800000000000000000000000000000000000000000000201", -- "401028774D7777C7B7666D1366EA432071274F89FF01E718", -- "0620048D28BCBD03B6249C99182B7C8CD19700C362C46A01", -- "3809B2B7CC1B28CC5A87926AAD83FD28789E81E2C9E3BF10", -- "17434386626D14F3DBF01760D9213A3E1CF37AEC437D668A", -- "20000000000000000000000050508CB89F652824E06B8173", 4 --}; --static const ECCurveParams ecCurve_X9_62_CHAR2_TNB191V3 = { -- "X9.62 C2-TNB191V3", ECField_GF2m, 191, -- "800000000000000000000000000000000000000000000201", -- "6C01074756099122221056911C77D77E77A777E7E7E77FCB", -- "71FE1AF926CF847989EFEF8DB459F66394D90F32AD3F15E8", -- "375D4CE24FDE434489DE8746E71786015009E66E38A926DD", -- "545A39176196575D985999366E6AD34CE0A77CD7127B06BE", -- "155555555555555555555555610C0B196812BFB6288A3EA3", 6 --}; --static const ECCurveParams ecCurve_X9_62_CHAR2_PNB208W1 = { -- "X9.62 C2-PNB208W1", ECField_GF2m, 208, -- "010000000000000000000000000000000800000000000000000007", -- "0000000000000000000000000000000000000000000000000000", -- "C8619ED45A62E6212E1160349E2BFA844439FAFC2A3FD1638F9E", -- "89FDFBE4ABE193DF9559ECF07AC0CE78554E2784EB8C1ED1A57A", -- "0F55B51A06E78E9AC38A035FF520D8B01781BEB1A6BB08617DE3", -- "000101BAF95C9723C57B6C21DA2EFF2D5ED588BDD5717E212F9D", 0xFE48 --}; --static const ECCurveParams ecCurve_X9_62_CHAR2_TNB239V1 = { -- "X9.62 C2-TNB239V1", ECField_GF2m, 239, -- "800000000000000000000000000000000000000000000000001000000001", -- "32010857077C5431123A46B808906756F543423E8D27877578125778AC76", -- "790408F2EEDAF392B012EDEFB3392F30F4327C0CA3F31FC383C422AA8C16", -- "57927098FA932E7C0A96D3FD5B706EF7E5F5C156E16B7E7C86038552E91D", -- "61D8EE5077C33FECF6F1A16B268DE469C3C7744EA9A971649FC7A9616305", -- "2000000000000000000000000000000F4D42FFE1492A4993F1CAD666E447", 4 --}; --static const ECCurveParams ecCurve_X9_62_CHAR2_TNB239V2 = { -- "X9.62 C2-TNB239V2", ECField_GF2m, 239, -- "800000000000000000000000000000000000000000000000001000000001", -- "4230017757A767FAE42398569B746325D45313AF0766266479B75654E65F", -- "5037EA654196CFF0CD82B2C14A2FCF2E3FF8775285B545722F03EACDB74B", -- "28F9D04E900069C8DC47A08534FE76D2B900B7D7EF31F5709F200C4CA205", -- "5667334C45AFF3B5A03BAD9DD75E2C71A99362567D5453F7FA6E227EC833", -- "1555555555555555555555555555553C6F2885259C31E3FCDF154624522D", 6 --}; --static const ECCurveParams ecCurve_X9_62_CHAR2_TNB239V3 = { -- "X9.62 C2-TNB239V3", ECField_GF2m, 239, -- "800000000000000000000000000000000000000000000000001000000001", -- "01238774666A67766D6676F778E676B66999176666E687666D8766C66A9F", -- "6A941977BA9F6A435199ACFC51067ED587F519C5ECB541B8E44111DE1D40", -- "70F6E9D04D289C4E89913CE3530BFDE903977D42B146D539BF1BDE4E9C92", -- "2E5A0EAF6E5E1305B9004DCE5C0ED7FE59A35608F33837C816D80B79F461", -- "0CCCCCCCCCCCCCCCCCCCCCCCCCCCCCAC4912D2D9DF903EF9888B8A0E4CFF", 0xA --}; --static const ECCurveParams ecCurve_X9_62_CHAR2_PNB272W1 = { -- "X9.62 C2-PNB272W1", ECField_GF2m, 272, -- "010000000000000000000000000000000000000000000000000000010000000000000B", -- "91A091F03B5FBA4AB2CCF49C4EDD220FB028712D42BE752B2C40094DBACDB586FB20", -- "7167EFC92BB2E3CE7C8AAAFF34E12A9C557003D7C73A6FAF003F99F6CC8482E540F7", -- "6108BABB2CEEBCF787058A056CBE0CFE622D7723A289E08A07AE13EF0D10D171DD8D", -- "10C7695716851EEF6BA7F6872E6142FBD241B830FF5EFCACECCAB05E02005DDE9D23", -- "000100FAF51354E0E39E4892DF6E319C72C8161603FA45AA7B998A167B8F1E629521", -- 0xFF06 --}; --static const ECCurveParams ecCurve_X9_62_CHAR2_PNB304W1 = { -- "X9.62 C2-PNB304W1", ECField_GF2m, 304, -- "010000000000000000000000000000000000000000000000000000000000000000000000000807", -- "FD0D693149A118F651E6DCE6802085377E5F882D1B510B44160074C1288078365A0396C8E681", -- "BDDB97E555A50A908E43B01C798EA5DAA6788F1EA2794EFCF57166B8C14039601E55827340BE", -- "197B07845E9BE2D96ADB0F5F3C7F2CFFBD7A3EB8B6FEC35C7FD67F26DDF6285A644F740A2614", -- "E19FBEB76E0DA171517ECF401B50289BF014103288527A9B416A105E80260B549FDC1B92C03B", -- "000101D556572AABAC800101D556572AABAC8001022D5C91DD173F8FB561DA6899164443051D", -- 0xFE2E --}; --static const ECCurveParams ecCurve_X9_62_CHAR2_TNB359V1 = { -- "X9.62 C2-TNB359V1", ECField_GF2m, 359, -- "800000000000000000000000000000000000000000000000000000000000000000000000100000000000000001", -- "5667676A654B20754F356EA92017D946567C46675556F19556A04616B567D223A5E05656FB549016A96656A557", -- "2472E2D0197C49363F1FE7F5B6DB075D52B6947D135D8CA445805D39BC345626089687742B6329E70680231988", -- "3C258EF3047767E7EDE0F1FDAA79DAEE3841366A132E163ACED4ED2401DF9C6BDCDE98E8E707C07A2239B1B097", -- "53D7E08529547048121E9C95F3791DD804963948F34FAE7BF44EA82365DC7868FE57E4AE2DE211305A407104BD", -- "01AF286BCA1AF286BCA1AF286BCA1AF286BCA1AF286BC9FB8F6B85C556892C20A7EB964FE7719E74F490758D3B", -- 0x4C --}; --static const ECCurveParams ecCurve_X9_62_CHAR2_PNB368W1 = { -- "X9.62 C2-PNB368W1", ECField_GF2m, 368, -- "0100000000000000000000000000000000000000000000000000000000000000000000002000000000000000000007", -- "E0D2EE25095206F5E2A4F9ED229F1F256E79A0E2B455970D8D0D865BD94778C576D62F0AB7519CCD2A1A906AE30D", -- "FC1217D4320A90452C760A58EDCD30C8DD069B3C34453837A34ED50CB54917E1C2112D84D164F444F8F74786046A", -- "1085E2755381DCCCE3C1557AFA10C2F0C0C2825646C5B34A394CBCFA8BC16B22E7E789E927BE216F02E1FB136A5F", -- "7B3EB1BDDCBA62D5D8B2059B525797FC73822C59059C623A45FF3843CEE8F87CD1855ADAA81E2A0750B80FDA2310", -- "00010090512DA9AF72B08349D98A5DD4C7B0532ECA51CE03E2D10F3B7AC579BD87E909AE40A6F131E9CFCE5BD967", -- 0xFF70 --}; --static const ECCurveParams ecCurve_X9_62_CHAR2_TNB431R1 = { -- "X9.62 C2-TNB431R1", ECField_GF2m, 431, -- "800000000000000000000000000000000000000000000000000000000000000000000000000001000000000000000000000000000001", -- "1A827EF00DD6FC0E234CAF046C6A5D8A85395B236CC4AD2CF32A0CADBDC9DDF620B0EB9906D0957F6C6FEACD615468DF104DE296CD8F", -- "10D9B4A3D9047D8B154359ABFB1B7F5485B04CEB868237DDC9DEDA982A679A5A919B626D4E50A8DD731B107A9962381FB5D807BF2618", -- "120FC05D3C67A99DE161D2F4092622FECA701BE4F50F4758714E8A87BBF2A658EF8C21E7C5EFE965361F6C2999C0C247B0DBD70CE6B7", -- "20D0AF8903A96F8D5FA2C255745D3C451B302C9346D9B7E485E7BCE41F6B591F3E8F6ADDCBB0BC4C2F947A7DE1A89B625D6A598B3760", -- "0340340340340340340340340340340340340340340340340340340323C313FAB50589703B5EC68D3587FEC60D161CC149C1AD4A91", -- 0x2760 --}; -- --/* SEC2 prime curves */ --static const ECCurveParams ecCurve_SECG_PRIME_112R1 = { -- "SECP-112R1", ECField_GFp, 112, -- "DB7C2ABF62E35E668076BEAD208B", -- "DB7C2ABF62E35E668076BEAD2088", -- "659EF8BA043916EEDE8911702B22", -- "09487239995A5EE76B55F9C2F098", -- "A89CE5AF8724C0A23E0E0FF77500", -- "DB7C2ABF62E35E7628DFAC6561C5", 1 --}; --static const ECCurveParams ecCurve_SECG_PRIME_112R2 = { -- "SECP-112R2", ECField_GFp, 112, -- "DB7C2ABF62E35E668076BEAD208B", -- "6127C24C05F38A0AAAF65C0EF02C", -- "51DEF1815DB5ED74FCC34C85D709", -- "4BA30AB5E892B4E1649DD0928643", -- "adcd46f5882e3747def36e956e97", -- "36DF0AAFD8B8D7597CA10520D04B", 4 --}; --static const ECCurveParams ecCurve_SECG_PRIME_128R1 = { -- "SECP-128R1", ECField_GFp, 128, -- "FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFF", -- "FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFC", -- "E87579C11079F43DD824993C2CEE5ED3", -- "161FF7528B899B2D0C28607CA52C5B86", -- "CF5AC8395BAFEB13C02DA292DDED7A83", -- "FFFFFFFE0000000075A30D1B9038A115", 1 --}; --static const ECCurveParams ecCurve_SECG_PRIME_128R2 = { -- "SECP-128R2", ECField_GFp, 128, -- "FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFF", -- "D6031998D1B3BBFEBF59CC9BBFF9AEE1", -- "5EEEFCA380D02919DC2C6558BB6D8A5D", -- "7B6AA5D85E572983E6FB32A7CDEBC140", -- "27B6916A894D3AEE7106FE805FC34B44", -- "3FFFFFFF7FFFFFFFBE0024720613B5A3", 4 --}; --static const ECCurveParams ecCurve_SECG_PRIME_160K1 = { -- "SECP-160K1", ECField_GFp, 160, -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC73", -- "0000000000000000000000000000000000000000", -- "0000000000000000000000000000000000000007", -- "3B4C382CE37AA192A4019E763036F4F5DD4D7EBB", -- "938CF935318FDCED6BC28286531733C3F03C4FEE", -- "0100000000000000000001B8FA16DFAB9ACA16B6B3", 1 --}; --static const ECCurveParams ecCurve_SECG_PRIME_160R1 = { -- "SECP-160R1", ECField_GFp, 160, -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFF", -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFC", -- "1C97BEFC54BD7A8B65ACF89F81D4D4ADC565FA45", -- "4A96B5688EF573284664698968C38BB913CBFC82", -- "23A628553168947D59DCC912042351377AC5FB32", -- "0100000000000000000001F4C8F927AED3CA752257", 1 --}; --static const ECCurveParams ecCurve_SECG_PRIME_160R2 = { -- "SECP-160R2", ECField_GFp, 160, -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC73", -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC70", -- "B4E134D3FB59EB8BAB57274904664D5AF50388BA", -- "52DCB034293A117E1F4FF11B30F7199D3144CE6D", -- "FEAFFEF2E331F296E071FA0DF9982CFEA7D43F2E", -- "0100000000000000000000351EE786A818F3A1A16B", 1 --}; --static const ECCurveParams ecCurve_SECG_PRIME_192K1 = { -- "SECP-192K1", ECField_GFp, 192, -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFEE37", -- "000000000000000000000000000000000000000000000000", -- "000000000000000000000000000000000000000000000003", -- "DB4FF10EC057E9AE26B07D0280B7F4341DA5D1B1EAE06C7D", -- "9B2F2F6D9C5628A7844163D015BE86344082AA88D95E2F9D", -- "FFFFFFFFFFFFFFFFFFFFFFFE26F2FC170F69466A74DEFD8D", 1 --}; --static const ECCurveParams ecCurve_SECG_PRIME_224K1 = { -- "SECP-224K1", ECField_GFp, 224, -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFE56D", -- "00000000000000000000000000000000000000000000000000000000", -- "00000000000000000000000000000000000000000000000000000005", -- "A1455B334DF099DF30FC28A169A467E9E47075A90F7E650EB6B7A45C", -- "7E089FED7FBA344282CAFBD6F7E319F7C0B0BD59E2CA4BDB556D61A5", -- "010000000000000000000000000001DCE8D2EC6184CAF0A971769FB1F7", 1 --}; --static const ECCurveParams ecCurve_SECG_PRIME_256K1 = { -- "SECP-256K1", ECField_GFp, 256, -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFC2F", -- "0000000000000000000000000000000000000000000000000000000000000000", -- "0000000000000000000000000000000000000000000000000000000000000007", -- "79BE667EF9DCBBAC55A06295CE870B07029BFCDB2DCE28D959F2815B16F81798", -- "483ADA7726A3C4655DA4FBFC0E1108A8FD17B448A68554199C47D08FFB10D4B8", -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141", 1 --}; -- --/* SEC2 binary curves */ --static const ECCurveParams ecCurve_SECG_CHAR2_113R1 = { -- "SECT-113R1", ECField_GF2m, 113, -- "020000000000000000000000000201", -- "003088250CA6E7C7FE649CE85820F7", -- "00E8BEE4D3E2260744188BE0E9C723", -- "009D73616F35F4AB1407D73562C10F", -- "00A52830277958EE84D1315ED31886", -- "0100000000000000D9CCEC8A39E56F", 2 --}; --static const ECCurveParams ecCurve_SECG_CHAR2_113R2 = { -- "SECT-113R2", ECField_GF2m, 113, -- "020000000000000000000000000201", -- "00689918DBEC7E5A0DD6DFC0AA55C7", -- "0095E9A9EC9B297BD4BF36E059184F", -- "01A57A6A7B26CA5EF52FCDB8164797", -- "00B3ADC94ED1FE674C06E695BABA1D", -- "010000000000000108789B2496AF93", 2 --}; --static const ECCurveParams ecCurve_SECG_CHAR2_131R1 = { -- "SECT-131R1", ECField_GF2m, 131, -- "080000000000000000000000000000010D", -- "07A11B09A76B562144418FF3FF8C2570B8", -- "0217C05610884B63B9C6C7291678F9D341", -- "0081BAF91FDF9833C40F9C181343638399", -- "078C6E7EA38C001F73C8134B1B4EF9E150", -- "0400000000000000023123953A9464B54D", 2 --}; --static const ECCurveParams ecCurve_SECG_CHAR2_131R2 = { -- "SECT-131R2", ECField_GF2m, 131, -- "080000000000000000000000000000010D", -- "03E5A88919D7CAFCBF415F07C2176573B2", -- "04B8266A46C55657AC734CE38F018F2192", -- "0356DCD8F2F95031AD652D23951BB366A8", -- "0648F06D867940A5366D9E265DE9EB240F", -- "0400000000000000016954A233049BA98F", 2 --}; --static const ECCurveParams ecCurve_SECG_CHAR2_163R1 = { -- "SECT-163R1", ECField_GF2m, 163, -- "0800000000000000000000000000000000000000C9", -- "07B6882CAAEFA84F9554FF8428BD88E246D2782AE2", -- "0713612DCDDCB40AAB946BDA29CA91F73AF958AFD9", -- "0369979697AB43897789566789567F787A7876A654", -- "00435EDB42EFAFB2989D51FEFCE3C80988F41FF883", -- "03FFFFFFFFFFFFFFFFFFFF48AAB689C29CA710279B", 2 --}; --static const ECCurveParams ecCurve_SECG_CHAR2_193R1 = { -- "SECT-193R1", ECField_GF2m, 193, -- "02000000000000000000000000000000000000000000008001", -- "0017858FEB7A98975169E171F77B4087DE098AC8A911DF7B01", -- "00FDFB49BFE6C3A89FACADAA7A1E5BBC7CC1C2E5D831478814", -- "01F481BC5F0FF84A74AD6CDF6FDEF4BF6179625372D8C0C5E1", -- "0025E399F2903712CCF3EA9E3A1AD17FB0B3201B6AF7CE1B05", -- "01000000000000000000000000C7F34A778F443ACC920EBA49", 2 --}; --static const ECCurveParams ecCurve_SECG_CHAR2_193R2 = { -- "SECT-193R2", ECField_GF2m, 193, -- "02000000000000000000000000000000000000000000008001", -- "0163F35A5137C2CE3EA6ED8667190B0BC43ECD69977702709B", -- "00C9BB9E8927D4D64C377E2AB2856A5B16E3EFB7F61D4316AE", -- "00D9B67D192E0367C803F39E1A7E82CA14A651350AAE617E8F", -- "01CE94335607C304AC29E7DEFBD9CA01F596F927224CDECF6C", -- "010000000000000000000000015AAB561B005413CCD4EE99D5", 2 --}; --static const ECCurveParams ecCurve_SECG_CHAR2_239K1 = { -- "SECT-239K1", ECField_GF2m, 239, -- "800000000000000000004000000000000000000000000000000000000001", -- "000000000000000000000000000000000000000000000000000000000000", -- "000000000000000000000000000000000000000000000000000000000001", -- "29A0B6A887A983E9730988A68727A8B2D126C44CC2CC7B2A6555193035DC", -- "76310804F12E549BDB011C103089E73510ACB275FC312A5DC6B76553F0CA", -- "2000000000000000000000000000005A79FEC67CB6E91F1C1DA800E478A5", 4 --}; -- --/* WTLS curves */ --static const ECCurveParams ecCurve_WTLS_1 = { -- "WTLS-1", ECField_GF2m, 113, -- "020000000000000000000000000201", -- "000000000000000000000000000001", -- "000000000000000000000000000001", -- "01667979A40BA497E5D5C270780617", -- "00F44B4AF1ECC2630E08785CEBCC15", -- "00FFFFFFFFFFFFFFFDBF91AF6DEA73", 2 --}; --static const ECCurveParams ecCurve_WTLS_8 = { -- "WTLS-8", ECField_GFp, 112, -- "FFFFFFFFFFFFFFFFFFFFFFFFFDE7", -- "0000000000000000000000000000", -- "0000000000000000000000000003", -- "0000000000000000000000000001", -- "0000000000000000000000000002", -- "0100000000000001ECEA551AD837E9", 1 --}; --static const ECCurveParams ecCurve_WTLS_9 = { -- "WTLS-9", ECField_GFp, 160, -- "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC808F", -- "0000000000000000000000000000000000000000", -- "0000000000000000000000000000000000000003", -- "0000000000000000000000000000000000000001", -- "0000000000000000000000000000000000000002", -- "0100000000000000000001CDC98AE0E2DE574ABF33", 1 --}; -- - /* mapping between ECCurveName enum and pointers to ECCurveParams */ - static const ECCurveParams *ecCurve_map[] = { -- NULL, /* ECCurve_noName */ -- &ecCurve_NIST_P192, /* ECCurve_NIST_P192 */ -- &ecCurve_NIST_P224, /* ECCurve_NIST_P224 */ -- &ecCurve_NIST_P256, /* ECCurve_NIST_P256 */ -- &ecCurve_NIST_P384, /* ECCurve_NIST_P384 */ -- &ecCurve_NIST_P521, /* ECCurve_NIST_P521 */ -- &ecCurve_NIST_K163, /* ECCurve_NIST_K163 */ -- &ecCurve_NIST_B163, /* ECCurve_NIST_B163 */ -- &ecCurve_NIST_K233, /* ECCurve_NIST_K233 */ -- &ecCurve_NIST_B233, /* ECCurve_NIST_B233 */ -- &ecCurve_NIST_K283, /* ECCurve_NIST_K283 */ -- &ecCurve_NIST_B283, /* ECCurve_NIST_B283 */ -- &ecCurve_NIST_K409, /* ECCurve_NIST_K409 */ -- &ecCurve_NIST_B409, /* ECCurve_NIST_B409 */ -- &ecCurve_NIST_K571, /* ECCurve_NIST_K571 */ -- &ecCurve_NIST_B571, /* ECCurve_NIST_B571 */ -- &ecCurve_X9_62_PRIME_192V2, /* ECCurve_X9_62_PRIME_192V2 */ -- &ecCurve_X9_62_PRIME_192V3, /* ECCurve_X9_62_PRIME_192V3 */ -- &ecCurve_X9_62_PRIME_239V1, /* ECCurve_X9_62_PRIME_239V1 */ -- &ecCurve_X9_62_PRIME_239V2, /* ECCurve_X9_62_PRIME_239V2 */ -- &ecCurve_X9_62_PRIME_239V3, /* ECCurve_X9_62_PRIME_239V3 */ -- &ecCurve_X9_62_CHAR2_PNB163V1, /* ECCurve_X9_62_CHAR2_PNB163V1 */ -- &ecCurve_X9_62_CHAR2_PNB163V2, /* ECCurve_X9_62_CHAR2_PNB163V2 */ -- &ecCurve_X9_62_CHAR2_PNB163V3, /* ECCurve_X9_62_CHAR2_PNB163V3 */ -- &ecCurve_X9_62_CHAR2_PNB176V1, /* ECCurve_X9_62_CHAR2_PNB176V1 */ -- &ecCurve_X9_62_CHAR2_TNB191V1, /* ECCurve_X9_62_CHAR2_TNB191V1 */ -- &ecCurve_X9_62_CHAR2_TNB191V2, /* ECCurve_X9_62_CHAR2_TNB191V2 */ -- &ecCurve_X9_62_CHAR2_TNB191V3, /* ECCurve_X9_62_CHAR2_TNB191V3 */ -- &ecCurve_X9_62_CHAR2_PNB208W1, /* ECCurve_X9_62_CHAR2_PNB208W1 */ -- &ecCurve_X9_62_CHAR2_TNB239V1, /* ECCurve_X9_62_CHAR2_TNB239V1 */ -- &ecCurve_X9_62_CHAR2_TNB239V2, /* ECCurve_X9_62_CHAR2_TNB239V2 */ -- &ecCurve_X9_62_CHAR2_TNB239V3, /* ECCurve_X9_62_CHAR2_TNB239V3 */ -- &ecCurve_X9_62_CHAR2_PNB272W1, /* ECCurve_X9_62_CHAR2_PNB272W1 */ -- &ecCurve_X9_62_CHAR2_PNB304W1, /* ECCurve_X9_62_CHAR2_PNB304W1 */ -- &ecCurve_X9_62_CHAR2_TNB359V1, /* ECCurve_X9_62_CHAR2_TNB359V1 */ -- &ecCurve_X9_62_CHAR2_PNB368W1, /* ECCurve_X9_62_CHAR2_PNB368W1 */ -- &ecCurve_X9_62_CHAR2_TNB431R1, /* ECCurve_X9_62_CHAR2_TNB431R1 */ -- &ecCurve_SECG_PRIME_112R1, /* ECCurve_SECG_PRIME_112R1 */ -- &ecCurve_SECG_PRIME_112R2, /* ECCurve_SECG_PRIME_112R2 */ -- &ecCurve_SECG_PRIME_128R1, /* ECCurve_SECG_PRIME_128R1 */ -- &ecCurve_SECG_PRIME_128R2, /* ECCurve_SECG_PRIME_128R2 */ -- &ecCurve_SECG_PRIME_160K1, /* ECCurve_SECG_PRIME_160K1 */ -- &ecCurve_SECG_PRIME_160R1, /* ECCurve_SECG_PRIME_160R1 */ -- &ecCurve_SECG_PRIME_160R2, /* ECCurve_SECG_PRIME_160R2 */ -- &ecCurve_SECG_PRIME_192K1, /* ECCurve_SECG_PRIME_192K1 */ -- &ecCurve_SECG_PRIME_224K1, /* ECCurve_SECG_PRIME_224K1 */ -- &ecCurve_SECG_PRIME_256K1, /* ECCurve_SECG_PRIME_256K1 */ -- &ecCurve_SECG_CHAR2_113R1, /* ECCurve_SECG_CHAR2_113R1 */ -- &ecCurve_SECG_CHAR2_113R2, /* ECCurve_SECG_CHAR2_113R2 */ -- &ecCurve_SECG_CHAR2_131R1, /* ECCurve_SECG_CHAR2_131R1 */ -- &ecCurve_SECG_CHAR2_131R2, /* ECCurve_SECG_CHAR2_131R2 */ -- &ecCurve_SECG_CHAR2_163R1, /* ECCurve_SECG_CHAR2_163R1 */ -- &ecCurve_SECG_CHAR2_193R1, /* ECCurve_SECG_CHAR2_193R1 */ -- &ecCurve_SECG_CHAR2_193R2, /* ECCurve_SECG_CHAR2_193R2 */ -- &ecCurve_SECG_CHAR2_239K1, /* ECCurve_SECG_CHAR2_239K1 */ -- &ecCurve_WTLS_1, /* ECCurve_WTLS_1 */ -- &ecCurve_WTLS_8, /* ECCurve_WTLS_8 */ -- &ecCurve_WTLS_9, /* ECCurve_WTLS_9 */ -- NULL /* ECCurve_pastLastCurve */ -+ NULL, /* ECCurve_noName */ -+ NULL, /* ECCurve_NIST_P192 */ -+ NULL, /* ECCurve_NIST_P224 */ -+ &ecCurve_NIST_P256, /* ECCurve_NIST_P256 */ -+ &ecCurve_NIST_P384, /* ECCurve_NIST_P384 */ -+ &ecCurve_NIST_P521, /* ECCurve_NIST_P521 */ -+ NULL, /* ECCurve_NIST_K163 */ -+ NULL, /* ECCurve_NIST_B163 */ -+ NULL, /* ECCurve_NIST_K233 */ -+ NULL, /* ECCurve_NIST_B233 */ -+ NULL, /* ECCurve_NIST_K283 */ -+ NULL, /* ECCurve_NIST_B283 */ -+ NULL, /* ECCurve_NIST_K409 */ -+ NULL, /* ECCurve_NIST_B409 */ -+ NULL, /* ECCurve_NIST_K571 */ -+ NULL, /* ECCurve_NIST_B571 */ -+ NULL, /* ECCurve_X9_62_PRIME_192V2 */ -+ NULL, /* ECCurve_X9_62_PRIME_192V3 */ -+ NULL, /* ECCurve_X9_62_PRIME_239V1 */ -+ NULL, /* ECCurve_X9_62_PRIME_239V2 */ -+ NULL, /* ECCurve_X9_62_PRIME_239V3 */ -+ NULL, /* ECCurve_X9_62_CHAR2_PNB163V1 */ -+ NULL, /* ECCurve_X9_62_CHAR2_PNB163V2 */ -+ NULL, /* ECCurve_X9_62_CHAR2_PNB163V3 */ -+ NULL, /* ECCurve_X9_62_CHAR2_PNB176V1 */ -+ NULL, /* ECCurve_X9_62_CHAR2_TNB191V1 */ -+ NULL, /* ECCurve_X9_62_CHAR2_TNB191V2 */ -+ NULL, /* ECCurve_X9_62_CHAR2_TNB191V3 */ -+ NULL, /* ECCurve_X9_62_CHAR2_PNB208W1 */ -+ NULL, /* ECCurve_X9_62_CHAR2_TNB239V1 */ -+ NULL, /* ECCurve_X9_62_CHAR2_TNB239V2 */ -+ NULL, /* ECCurve_X9_62_CHAR2_TNB239V3 */ -+ NULL, /* ECCurve_X9_62_CHAR2_PNB272W1 */ -+ NULL, /* ECCurve_X9_62_CHAR2_PNB304W1 */ -+ NULL, /* ECCurve_X9_62_CHAR2_TNB359V1 */ -+ NULL, /* ECCurve_X9_62_CHAR2_PNB368W1 */ -+ NULL, /* ECCurve_X9_62_CHAR2_TNB431R1 */ -+ NULL, /* ECCurve_SECG_PRIME_112R1 */ -+ NULL, /* ECCurve_SECG_PRIME_112R2 */ -+ NULL, /* ECCurve_SECG_PRIME_128R1 */ -+ NULL, /* ECCurve_SECG_PRIME_128R2 */ -+ NULL, /* ECCurve_SECG_PRIME_160K1 */ -+ NULL, /* ECCurve_SECG_PRIME_160R1 */ -+ NULL, /* ECCurve_SECG_PRIME_160R2 */ -+ NULL, /* ECCurve_SECG_PRIME_192K1 */ -+ NULL, /* ECCurve_SECG_PRIME_224K1 */ -+ NULL, /* ECCurve_SECG_PRIME_256K1 */ -+ NULL, /* ECCurve_SECG_CHAR2_113R1 */ -+ NULL, /* ECCurve_SECG_CHAR2_113R2 */ -+ NULL, /* ECCurve_SECG_CHAR2_131R1 */ -+ NULL, /* ECCurve_SECG_CHAR2_131R2 */ -+ NULL, /* ECCurve_SECG_CHAR2_163R1 */ -+ NULL, /* ECCurve_SECG_CHAR2_193R1 */ -+ NULL, /* ECCurve_SECG_CHAR2_193R2 */ -+ NULL, /* ECCurve_SECG_CHAR2_239K1 */ -+ NULL, /* ECCurve_WTLS_1 */ -+ NULL, /* ECCurve_WTLS_8 */ -+ NULL, /* ECCurve_WTLS_9 */ -+ NULL /* ECCurve_pastLastCurve */ - }; - - #endif -Index: mozilla/security/nss/lib/freebl/manifest.mn -diff -u mozilla/security/nss/lib/freebl/manifest.mn:1.44.2.1 mozilla/security/nss/lib/freebl/manifest.mn:1.44.2.2 ---- mozilla/security/nss/lib/freebl/manifest.mn:1.44.2.1 Fri Mar 31 00:26:40 2006 -+++ mozilla/security/nss/lib/freebl/manifest.mn Fri Apr 28 03:35:29 2006 -@@ -104,11 +104,13 @@ - ECL_HDRS = ecl-exp.h ecl.h ec2.h ecp.h ecl-priv.h - ifdef NSS_ENABLE_ECC - ECL_SRCS = ecl.c ecl_curve.c ecl_mult.c ecl_gf.c \ -- ec2_aff.c ec2_mont.c ec2_proj.c \ -- ec2_163.c ec2_193.c ec2_233.c \ - ecp_aff.c ecp_jac.c ecp_mont.c \ -- ecp_192.c ecp_224.c ecp_256.c ecp_384.c ecp_521.c \ - ec_naf.c ecp_jm.c -+ifdef NSS_ECC_MORE_THAN_SUITE_B -+ECL_SRCS += ec2_aff.c ec2_mont.c ec2_proj.c \ -+ ec2_163.c ec2_193.c ec2_233.c \ -+ ecp_192.c ecp_224.c ecp_256.c ecp_384.c ecp_521.c -+endif - else - ECL_SRCS = $(NULL) - endif -Index: mozilla/security/nss/lib/cryptohi/secsign.c -diff -u mozilla/security/nss/lib/cryptohi/secsign.c:1.14.2.2 mozilla/security/nss/lib/cryptohi/secsign.c:1.14.2.3 ---- mozilla/security/nss/lib/cryptohi/secsign.c:1.14.2.2 Thu Mar 2 00:12:26 2006 -+++ mozilla/security/nss/lib/cryptohi/secsign.c Fri Apr 28 03:35:29 2006 -@@ -37,7 +37,7 @@ - * the terms of any one of the MPL, the GPL or the LGPL. - * - * ***** END LICENSE BLOCK ***** */ --/* $Id: secsign.c,v 1.14.2.2 2006/03/02 00:12:26 wtchang%redhat.com Exp $ */ -+/* $Id: secsign.c,v 1.14.2.3 2006/04/28 03:35:29 rrelyea%redhat.com Exp $ */ - - #include - #include "cryptohi.h" -@@ -157,6 +157,13 @@ - return 0; - } - -+#ifndef NSS_ECC_MORE_THAN_SUITE_B -+ if (key->keyType == ecKey) { -+ PORT_SetError(SEC_ERROR_INVALID_ALGORITHM); -+ return 0; -+ } -+#endif -+ - cx = (SGNContext*) PORT_ZAlloc(sizeof(SGNContext)); - if (cx) { - cx->hashalg = hashalg; diff --git a/nss-smartcard-auth.patch b/nss-smartcard-auth.patch deleted file mode 100644 index 66c4567..0000000 --- a/nss-smartcard-auth.patch +++ /dev/null @@ -1,83 +0,0 @@ -Index: mozilla/security/nss/lib/pk11wrap/pk11auth.c -=================================================================== -RCS file: /cvsroot/mozilla/security/nss/lib/pk11wrap/pk11auth.c,v -retrieving revision 1.5 -diff -u -r1.5 pk11auth.c ---- mozilla/security/nss/lib/pk11wrap/pk11auth.c 29 Sep 2005 23:44:39 -0000 1.5 -+++ mozilla/security/nss/lib/pk11wrap/pk11auth.c 12 Jan 2007 01:23:20 -0000 -@@ -84,6 +84,8 @@ - CK_RV crv; - SECStatus rv; - int64 currtime = PR_Now(); -+ PRBool mustRetry; -+ int retry = 0; - - if (slot->protectedAuthPath) { - len = 0; -@@ -95,27 +97,46 @@ - len = PORT_Strlen(pw); - } - -- PK11_EnterSlotMonitor(slot); -- crv = PK11_GETTAB(slot)->C_Login(slot->session,CKU_USER, -+ do { -+ PK11_EnterSlotMonitor(slot); -+ crv = PK11_GETTAB(slot)->C_Login(slot->session,CKU_USER, - (unsigned char *)pw,len); -- slot->lastLoginCheck = 0; -- PK11_ExitSlotMonitor(slot); -- switch (crv) { -- /* if we're already logged in, we're good to go */ -- case CKR_OK: -- slot->authTransact = PK11_Global.transaction; -- case CKR_USER_ALREADY_LOGGED_IN: -- slot->authTime = currtime; -- rv = SECSuccess; -- break; -- case CKR_PIN_INCORRECT: -- PORT_SetError(SEC_ERROR_BAD_PASSWORD); -- rv = SECWouldBlock; /* everything else is ok, only the pin is bad */ -- break; -- default: -- PORT_SetError(PK11_MapError(crv)); -- rv = SECFailure; /* some failure we can't fix by retrying */ -- } -+ slot->lastLoginCheck = 0; -+ mustRetry = PR_FALSE; -+ PK11_ExitSlotMonitor(slot); -+ switch (crv) { -+ /* if we're already logged in, we're good to go */ -+ case CKR_OK: -+ slot->authTransact = PK11_Global.transaction; -+ case CKR_USER_ALREADY_LOGGED_IN: -+ slot->authTime = currtime; -+ rv = SECSuccess; -+ break; -+ case CKR_PIN_INCORRECT: -+ PORT_SetError(SEC_ERROR_BAD_PASSWORD); -+ rv = SECWouldBlock; /* everything else is ok, only the pin is bad */ -+ break; -+ /* someone called reset while we fetched the password, try again once -+ * if the token is still there. */ -+ case CKR_SESSION_HANDLE_INVALID: -+ case CKR_SESSION_CLOSED: -+ if (retry++ == 0) { -+ rv = PK11_InitToken(slot,PR_FALSE); -+ if (rv == SECSuccess) { -+ if (slot->session != CK_INVALID_SESSION) { -+ mustRetry = PR_TRUE; -+ } else { -+ PORT_SetError(PK11_MapError(crv)); -+ rv = SECFailure; -+ } -+ } -+ break; -+ } -+ default: -+ PORT_SetError(PK11_MapError(crv)); -+ rv = SECFailure; /* some failure we can't fix by retrying */ -+ } -+ } while (mustRetry); - return rv; - } - diff --git a/nss-use-netstat-hack.patch b/nss-use-netstat-hack.patch deleted file mode 100644 index 7469349..0000000 --- a/nss-use-netstat-hack.patch +++ /dev/null @@ -1,11 +0,0 @@ ---- ./mozilla/security/coreconf/config.mk.org 2007-05-25 01:53:04.000000000 +0200 -+++ ./mozilla/security/coreconf/config.mk 2007-05-25 01:52:58.000000000 +0200 -@@ -185,3 +185,8 @@ - ifdef NSS_ALLOW_UNSUPPORTED_CRITICAL - DEFINES += -DNSS_ALLOW_UNSUPPORTED_CRITICAL - endif -+ -+ifdef USE_NETSTAT_HACK -+DEFINES += -DSOLARIS -+INCLUDES += -I../fake -+endif diff --git a/nss.spec b/nss.spec index 9bd98ac..6e103fc 100644 --- a/nss.spec +++ b/nss.spec @@ -1,44 +1,35 @@ -%define nspr_version 4.6.2 +%define nspr_version 4.6.99 %define unsupported_tools_directory %{_libdir}/nss/unsupported-tools -%define fips_source_version 3.11.5 -%define ckfw_source_version 3.12-alpha -%define ckbi_version 1.64 Summary: Network Security Services Name: nss -Version: 3.11.7 -Release: 10%{?dist} +Version: 3.11.99.2 +Release: 1%{?dist} License: MPLv1.1 or GPLv2+ or LGPLv2+ URL: http://www.mozilla.org/projects/security/pki/nss/ Group: System Environment/Libraries Requires: nspr >= %{nspr_version} +Requires: sqlite BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) BuildRequires: nspr-devel >= %{nspr_version} +BuildRequires: sqlite-devel BuildRequires: pkgconfig BuildRequires: gawk Provides: mozilla-nss Obsoletes: mozilla-nss -#Source0: %{name}-%{version}-no-fbst.tar.gz -Source0: %{name}-%{version}-no-fbst-with-ckbi-%{ckbi_version}.tar.gz -# ckbi is the builtin roots module which may get released separately. +Source0: %{name}-%{version}-stripped.tar.bz2 Source1: nss.pc.in Source2: nss-config.in Source3: blank-cert8.db Source4: blank-key3.db Source5: blank-secmod.db -Source7: fake-kstat.h Source8: nss-prelink.conf -Source10: %{name}-%{fips_source_version}-fbst-stripped.tar.gz -Source11: %{name}-%{ckfw_source_version}-ckfw.tar.gz -Source12: %{name}-%{ckfw_source_version}-pem.tar.gz +Source12: %{name}-pem.tar.gz Patch1: nss-no-rpath.patch -Patch2: nss-smartcard-auth.patch -Patch3: nss-use-netstat-hack.patch -Patch4: nss-decouple-softokn.patch -Patch5: nss-disable-build-freebl-softoken.patch +Patch2: nss-nolocalsql.patch Patch6: nss-enable-pem.patch Patch7: nss-create-obj.patch @@ -91,52 +82,13 @@ low level services. %prep %setup -q -%setup -q -T -D -n %{name}-%{version} -a 10 -%setup -q -T -D -n %{name}-%{version} -a 11 %setup -q -T -D -n %{name}-%{version} -a 12 -%define old_nss_lib %{name}-%{fips_source_version}/mozilla/security/nss/lib -%define new_nss_lib mozilla/security/nss/lib -%define new_ckfw_lib %{name}-%{ckfw_source_version}/mozilla/security/nss/lib - -# Ensure we will not use new freebl/softoken code -rm -rf %{new_nss_lib}/freebl -rm -rf %{new_nss_lib}/softoken - -# However, in order to build newer NSS we need some exports -cp -a %{old_nss_lib}/freebl %{new_nss_lib} -cp -a %{old_nss_lib}/softoken %{new_nss_lib} - -# set up ckfw -rm -rf %{new_nss_lib}/ckfw -cp -a %{new_ckfw_lib}/ckfw %{new_nss_lib} - -# Ensure the newer NSS tree will not build code, except the loader -mv -i %{new_nss_lib}/freebl/loader.c %{new_nss_lib}/freebl/loader.c.save -rm -rf %{new_nss_lib}/freebl/*.c %{new_nss_lib}/freebl/*.s -rm -rf %{new_nss_lib}/softoken/*.c %{new_nss_lib}/softoken/*.s -mv -i %{new_nss_lib}/freebl/loader.c.save %{new_nss_lib}/freebl/loader.c - -# These currently don't build without freebl/softoken in the same tree -rm -rf mozilla/security/nss/cmd/bltest -rm -rf mozilla/security/nss/cmd/fipstest -rm -rf mozilla/security/nss/cmd/certcgi - -# Apply the patches to the newer NSS tree %patch1 -p0 -%patch2 -p0 -b .smartcard-auth -%patch4 -p0 -b .decouple-softokn -%patch5 -p0 -b .nofbst +%patch2 -p0 %patch6 -p0 -b .libpem %patch7 -p0 -b .create-obj -# Apply the patches to the tree where we build freebl/softoken -cd nss-%{fips_source_version} -%patch3 -p0 -b .use-netstat-hack -%{__mkdir_p} mozilla/security/nss/lib/fake/ -cp -i %{SOURCE7} mozilla/security/nss/lib/fake/kstat.h -cd .. - %build @@ -171,26 +123,6 @@ export USE_64 # NSS_ENABLE_ECC=1 # export NSS_ENABLE_ECC -##### first, build freebl and softokn shared libraries - -cd nss-%{fips_source_version} -%{__make} -C ./mozilla/security/coreconf -%{__make} -C ./mozilla/security/dbm -%{__make} -C ./mozilla/security/nss export -%{__make} -C ./mozilla/security/nss/lib/base -%{__make} -C ./mozilla/security/nss/lib/util -%{__make} -C ./mozilla/security/nss/lib/freebl -touch ./mozilla/security/nss/lib/freebl/unix_rand.c -rm -f ./mozilla/security/nss/lib/freebl/*/*/libfreebl3* -rm -f ./mozilla/security/nss/lib/freebl/*/*/sysrand* -USE_NETSTAT_HACK=1 %{__make} -C ./mozilla/security/nss/lib/freebl -%{__make} -C ./mozilla/security/nss/lib/freebl install -%{__make} -C ./mozilla/security/nss/lib/softoken -%{__make} -C ./mozilla/security/nss/lib/softoken install -cd .. - -##### second, build all the rest of NSS - %{__make} -C ./mozilla/security/coreconf %{__make} -C ./mozilla/security/dbm %{__make} -C ./mozilla/security/nss @@ -236,14 +168,7 @@ chmod 755 $RPM_BUILD_ROOT/%{_bindir}/nss-config %{__mkdir_p} $RPM_BUILD_ROOT/%{unsupported_tools_directory} # Copy the binary libraries we want -for file in libsoftokn3.so libfreebl3.so -do - %{__install} -m 755 nss-%{fips_source_version}/mozilla/dist/*.OBJ/lib/$file \ - $RPM_BUILD_ROOT/%{_libdir} -done - -# Copy the binary libraries we want -for file in libnss3.so libssl3.so libsmime3.so libnssckbi.so libnsspem.so +for file in libsoftokn3.so libfreebl3.so libnss3.so libssl3.so libsmime3.so libnssckbi.so libnsspem.so libnssdbm3.so do %{__install} -m 755 mozilla/dist/*.OBJ/lib/$file $RPM_BUILD_ROOT/%{_libdir} done @@ -278,12 +203,15 @@ do %{__install} -m 755 mozilla/dist/*.OBJ/bin/$file $RPM_BUILD_ROOT/%{unsupported_tools_directory} done -# Copy the include files we want from freebl/softoken sources -# and remove those files from the other area -for file in blapit.h shsign.h ecl-exp.h pkcs11.h pkcs11f.h pkcs11p.h pkcs11t.h pkcs11n.h pkcs11u.h +# For now, we don't want any pkix files to be public +for file in mozilla/dist/public/nss/pkix*.h +do + rm $file +done + +# For now, we don't want these files to be public +for file in sdb.h sftkdbt.h do - %{__install} -m 644 nss-%{fips_source_version}/mozilla/dist/public/nss/$file \ - $RPM_BUILD_ROOT/%{_includedir}/nss3 rm mozilla/dist/public/nss/$file done @@ -311,6 +239,7 @@ done %files %defattr(-,root,root) %{_libdir}/libnss3.so +%{_libdir}/libnssdbm3.so %{_libdir}/libssl3.so %{_libdir}/libsmime3.so %{_libdir}/libsoftokn3.so @@ -457,6 +386,9 @@ done %changelog +* Wed Nov 07 2007 Kai Engert - 3.11.99.2-1 +- NSS 3.12 alpha 2 + * Wed Oct 10 2007 Kai Engert - 3.11.7-10 - Add /etc/prelink.conf.d/nss-prelink.conf in order to blacklist our signed libraries and protect them from modification. diff --git a/sources b/sources index b6329f6..5804eb3 100644 --- a/sources +++ b/sources @@ -1,4 +1,2 @@ -68c5e1bd8ba091e5a50babcd9e552bc5 nss-3.11.5-fbst-stripped.tar.gz -c1053d1e001a5b1eb4b7c296a968ca5c nss-3.11.7-no-fbst-with-ckbi-1.64.tar.gz -baa96599af6f0a2b656479d8e4efd58f nss-3.12-alpha-ckfw.tar.gz -cb4e4fc7c06ad3b02178ed453273abec nss-3.12-alpha-pem.tar.gz +23ed668befdac5dbbb8b30dc96a3f332 nss-3.11.99.2-stripped.tar.bz2 +d656d49b02fe756bae4942acc90f61a4 nss-pem.tar.gz