Add FIPS mode detection
On FIPS-based systems, DES3 is not used at all, and the default session type is UDS-based Xvnc rather than TCP-based Xvnc.
This commit is contained in:
@@ -4282,6 +4282,29 @@ g_no_new_privs(void)
|
||||
#endif
|
||||
}
|
||||
|
||||
|
||||
/*****************************************************************************/
|
||||
int
|
||||
g_fips_mode_enabled(void)
|
||||
{
|
||||
int rv = 0;
|
||||
#if defined (__linux)
|
||||
char buff[16];
|
||||
int fd = open("/proc/sys/crypto/fips_enabled", O_RDONLY);
|
||||
|
||||
if (fd >= 0)
|
||||
{
|
||||
if (read(fd, buff, sizeof(buff)) > 0)
|
||||
{
|
||||
rv = (buff[0] != '0');
|
||||
}
|
||||
|
||||
close(fd);
|
||||
}
|
||||
#endif
|
||||
return rv;
|
||||
}
|
||||
|
||||
/*****************************************************************************/
|
||||
void
|
||||
g_qsort(void *base, size_t nitems, size_t size,
|
||||
|
||||
+9
-1
@@ -428,6 +428,14 @@ int g_tcp4_bind_address(int sck, const char *port, const char *address);
|
||||
int g_tcp6_socket(void);
|
||||
int g_tcp6_bind_address(int sck, const char *port, const char *address);
|
||||
int g_no_new_privs(void);
|
||||
/**
|
||||
* Query whether FIPS mode is enabled
|
||||
*
|
||||
* In FIPS mode, some cryptographic algorithms are disabled
|
||||
*
|
||||
* @return 1 -> FIPS mode enabled, 0 -> FIPS mode disabled or unknown
|
||||
*/
|
||||
int g_fips_mode_enabled(void);
|
||||
void
|
||||
g_qsort(void *base, size_t nitems, size_t size,
|
||||
int (*compar)(const void *, const void *));
|
||||
@@ -461,7 +469,7 @@ g_malloc_nofail(size_t size);
|
||||
|
||||
/** Allocate memory with error-checking
|
||||
*
|
||||
* @param Number of elementst to allocate
|
||||
* @param Number of elements to allocate
|
||||
* @param size Size of each element
|
||||
* @return Allocated memory
|
||||
*
|
||||
|
||||
Reference in New Issue
Block a user