From: Felix Fietkau Date: Sat, 10 Dec 2016 10:22:58 +0000 (+0100) Subject: mbedtls: sync with polarssl config X-Git-Url: http://git.lede-project.org./?a=commitdiff_plain;h=732c24a0cac4293b058c99ff7867fd13a2670eca;p=openwrt%2Fstaging%2Fthess.git mbedtls: sync with polarssl config One of those changes is re-enabling blowfish support to make openvpn-mbedtls compatible with common configurations Signed-off-by: Felix Fietkau --- diff --git a/package/libs/mbedtls/patches/200-config.patch b/package/libs/mbedtls/patches/200-config.patch index 75d8342d3e..9e477ef083 100644 --- a/package/libs/mbedtls/patches/200-config.patch +++ b/package/libs/mbedtls/patches/200-config.patch @@ -36,6 +36,16 @@ #define MBEDTLS_ECP_DP_SECP256K1_ENABLED #define MBEDTLS_ECP_DP_BP256R1_ENABLED #define MBEDTLS_ECP_DP_BP384R1_ENABLED +@@ -476,8 +476,8 @@ + * Requires: MBEDTLS_HMAC_DRBG_C + * + * Comment this macro to disable deterministic ECDSA. +- */ + #define MBEDTLS_ECDSA_DETERMINISTIC ++ */ + + /** + * \def MBEDTLS_KEY_EXCHANGE_PSK_ENABLED @@ -523,7 +523,7 @@ * MBEDTLS_TLS_DHE_PSK_WITH_3DES_EDE_CBC_SHA * MBEDTLS_TLS_DHE_PSK_WITH_RC4_128_SHA @@ -45,6 +55,16 @@ /** * \def MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED +@@ -542,8 +542,8 @@ + * MBEDTLS_TLS_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 + * MBEDTLS_TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA + * MBEDTLS_TLS_ECDHE_PSK_WITH_RC4_128_SHA +- */ + #define MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED ++ */ + + /** + * \def MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED @@ -568,7 +568,7 @@ * MBEDTLS_TLS_RSA_PSK_WITH_3DES_EDE_CBC_SHA * MBEDTLS_TLS_RSA_PSK_WITH_RC4_128_SHA @@ -116,6 +136,16 @@ /** * \def MBEDTLS_SSL_ALL_ALERT_MESSAGES +@@ -1234,8 +1234,8 @@ + * callbacks are provided by MBEDTLS_SSL_TICKET_C. + * + * Comment this macro to disable support for SSL session tickets +- */ + #define MBEDTLS_SSL_SESSION_TICKETS ++ */ + + /** + * \def MBEDTLS_SSL_EXPORT_KEYS @@ -1265,7 +1265,7 @@ * * Comment this macro to disable support for truncated HMAC in SSL @@ -125,6 +155,16 @@ /** * \def MBEDTLS_THREADING_ALT +@@ -1299,8 +1299,8 @@ + * Requires: MBEDTLS_VERSION_C + * + * Comment this to disable run-time checking and save ROM space +- */ + #define MBEDTLS_VERSION_FEATURES ++ */ + + /** + * \def MBEDTLS_X509_ALLOW_EXTENSIONS_NON_V3 @@ -1501,7 +1501,7 @@ * MBEDTLS_TLS_RSA_PSK_WITH_RC4_128_SHA * MBEDTLS_TLS_PSK_WITH_RC4_128_SHA @@ -134,15 +174,6 @@ /** * \def MBEDTLS_ASN1_PARSE_C -@@ -1566,7 +1566,7 @@ - * - * Module: library/blowfish.c - */ --#define MBEDTLS_BLOWFISH_C -+//#define MBEDTLS_BLOWFISH_C - - /** - * \def MBEDTLS_CAMELLIA_C @@ -1621,7 +1621,7 @@ * MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_GCM_SHA256 * MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_CBC_SHA256 @@ -179,6 +210,16 @@ /** * \def MBEDTLS_DES_C +@@ -1880,8 +1880,8 @@ + * Requires: MBEDTLS_MD_C + * + * Uncomment to enable the HMAC_DRBG random number geerator. +- */ + #define MBEDTLS_HMAC_DRBG_C ++ */ + + /** + * \def MBEDTLS_MD_C @@ -2158,7 +2158,7 @@ * Caller: library/mbedtls_md.c * @@ -188,6 +229,36 @@ /** * \def MBEDTLS_RSA_C +@@ -2235,8 +2235,8 @@ + * Caller: + * + * Requires: MBEDTLS_SSL_CACHE_C +- */ + #define MBEDTLS_SSL_CACHE_C ++ */ + + /** + * \def MBEDTLS_SSL_COOKIE_C +@@ -2257,8 +2257,8 @@ + * Caller: + * + * Requires: MBEDTLS_CIPHER_C +- */ + #define MBEDTLS_SSL_TICKET_C ++ */ + + /** + * \def MBEDTLS_SSL_CLI_C +@@ -2357,8 +2357,8 @@ + * Module: library/version.c + * + * This module provides run-time version information. +- */ + #define MBEDTLS_VERSION_C ++ */ + + /** + * \def MBEDTLS_X509_USE_C @@ -2468,7 +2468,7 @@ * Module: library/xtea.c * Caller: